Updated on 2026-07-22 GMT+08:00

Creating a Permanent Access Key

Function

This API is used to create a permanent access key for an IAM user.

AKs or SKs are identity credentials for using development tools (API, CLI, and SDK) to access resources and cannot be used for console login. AK is a unique identifier used in conjunction with SK to sign requests cryptographically, ensuring that the requests are secret, complete, and correct.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam:credentials:createCredentialV5

Write

user *

  • g:ResourceTag/<tag-key>

  • iam:ResourceIsRootUser

-

-

URI

POST /v5/users/{user_id}/access-keys

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

user_id

Yes

String

Definition:

IAM user ID.

Constraints:

The user ID must exist and be valid.

Range:

32 bits.

Default Value:

N/A

Request Parameters

None

Response Parameters

Status code: 201

Table 2 Response body parameters

Parameter

Type

Description

access_key

access_key object

Definition:

Created permanent access key.

Range:

N/A

Table 3 access_key

Parameter

Type

Description

user_id

String

Definition:

IAM user ID, which is globally unique.

Range:

N/A

access_key_id

String

Definition :

Permanent access key ID (AK). For details about how to obtain it, see Reference.

Range:

N/A.

created_at

String

Definition:

Time when the access key was created.

Range:

N/A

secret_access_key

String

Definition :

Created SK. For details about how to obtain it, see Reference.

Range:

N/A.

status

String

Definition:

Access key status.

Range:

active or inactive.

Status code: 400

Table 4 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 403

Table 5 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Status code: 404

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Example Requests

Creating a permanent access key for an IAM user

POST https://{endpoint}/v5/users/{user_id}/access-keys

Example Responses

Status code: 201

Successful

{
  "access_key" : {
    "user_id" : "user",
    "access_key_id" : "access",
    "created_at" : "2023-09-13T06:51:20.550Z",
    "secret_access_key" : "secret",
    "status" : "active"
  }
}

Status Codes

Status Code

Description

201

Successful

400

Bad request

403

Forbidden

404

Not found

Error Codes

See Error Codes.