# Let an app or your accountant integrate

Mint an API key with an exact scope — the secret shows once, and it expires on schedule.

Integrations · a play in 1 step.

## The steps

1. Mint the key and copy the once-only secret to the integrating side. — [mintApiKey](/reference/system-and-integration-setup/mintApiKey/)

## The calls

Every operation this use case runs, in the order it first appears, with the request and the response its reference page shows.

### mintApiKey

[mintApiKey](/reference/system-and-integration-setup/mintApiKey/) — mutation · Mint an API key — a machine credential for your integrations.

**Example request**

```graphql
mutation ExampleMintApiKey($input: MintApiKeyInput!) {
  mintApiKey(input: $input) {
    secret
  }
}
```

Variables:

```json
{
  "input": {
    "caption": "Blue jeans",
    "descriptors": [
      {
        "service": "<service>",
        "action": "<action>",
        "polarity": "allow"
      }
    ],
    "expiresAt": "2027-01-31T00:00:00.000Z"
  }
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "mintApiKey": {
      "secret": "<your key secret>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```
