> ## Documentation Index
> Fetch the complete documentation index at: https://docs.moderationapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Management API

> Create, change, copy, and delete projects and channels from your own code with an organization API key.

The management API lets you set up [projects and channels](/get-started/concepts) from your own code instead of the dashboard. Use it when you run moderation for many products or customers and set up the same configuration again and again.

You call it with an **organization key**. An organization key manages projects and channels across your organization. It can't moderate content. To moderate content, use a project's secret key. See [Authentication](/api-reference/authentication).

<Note>
  The management API is available on Enterprise plans. To enable it, contact
  [support@moderationapi.com](mailto:support@moderationapi.com).
</Note>

## Prerequisites

* An Enterprise plan.
* The **Admin** or **Owner** role in your organization. Only these roles can create organization keys.

## Create an organization key

<Steps>
  <Step title="Open API keys">
    In the [dashboard](https://dash.moderationapi.com), go to **Settings → API keys** and click **Create key**.
  </Step>

  <Step title="Choose its access">
    * **Name**: a label so you can recognize the key, for example the tool that uses it.
    * **Permissions**: pick **None**, **Read**, or **Write** for projects and for channels. Write includes read.
    * **Projects**: leave empty to reach every project, or pick the projects the key can reach.
    * **Expires**: **Never**, **30 days**, **90 days**, or **365 days**.
  </Step>

  <Step title="Copy the key">
    Copy the key and store it in a secret manager. You can't see it again after you close the dialog.
  </Step>
</Steps>

Organization keys start with `sk_org_`, so you and secret scanners can tell them apart from project keys.

## Permissions

Each endpoint needs one permission on the key:

| Permission | Endpoints |
| - | - |
| `projects:read` | [List projects](/api-reference/projects/list-projects), [get a project](/api-reference/projects/get-a-project) |
| `projects:write` | [Create](/api-reference/projects/create-a-project), [update](/api-reference/projects/update-a-project), [duplicate](/api-reference/projects/duplicate-a-project), and [delete](/api-reference/projects/delete-a-project) a project |
| `channels:read` | [List channels](/api-reference/channels/list-channels), [get a channel](/api-reference/channels/get-a-channel) |
| `channels:write` | [Create](/api-reference/channels/create-a-channel), [update](/api-reference/channels/update-a-channel), [duplicate](/api-reference/channels/duplicate-a-channel), and [delete](/api-reference/channels/delete-a-channel) a channel |

An organization key can also call [Get account details](/api-reference/account/get-account-details), so you can check that the key works.

### Keys limited to some projects

A key limited to some projects only sees those projects and their channels. Other projects return `404 Not Found`. A limited key can't create or duplicate projects, because the new project would fall outside its limit. Use a key that reaches every project for that.

## Example: set up a new project

Create a project. The response includes the new project's `secretKey`, which you use to moderate content in that project. The other project endpoints don't return it. You can also find it in the dashboard under **Project → Configure → API keys**.

```bash theme={"theme":"nord"}
curl -X POST https://api.moderationapi.com/v1/projects \
  -H "Authorization: Bearer $MODERATION_ORG_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Acme Marketplace",
    "domain": "acme.example"
  }'
```

Every new project comes with one channel, a review queue, and a secret key. When you give a `domain` or `context`, the project suggests policies for the platform.

Add a channel for another surface of your product:

```bash theme={"theme":"nord"}
curl -X POST https://api.moderationapi.com/v1/projects/PROJECT_ID/channels \
  -H "Authorization: Bearer $MODERATION_ORG_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Reviews",
    "key": "reviews",
    "contentType": "review"
  }'
```

Then moderate content with the project's secret key, and pass the channel's `key` as `channel`:

```bash theme={"theme":"nord"}
curl -X POST https://api.moderationapi.com/v1/moderate \
  -H "Authorization: Bearer $PROJECT_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "content": { "type": "text", "text": "Great seller, fast shipping!" },
    "channel": "reviews"
  }'
```

## Copy a setup

To reuse a configuration you already tuned, duplicate it instead of building it again:

* **[Duplicate a project](/api-reference/projects/duplicate-a-project)** copies its settings, every channel with its policies, rules and wordlists, its moderation actions, and its review queues. The copy gets its own secret key. Webhooks, integrations, API keys, and content aren't copied.
* **[Duplicate a channel](/api-reference/channels/duplicate-a-channel)** copies a channel inside its project with every setting, policy, rule, and wordlist. Use it to try a change next to the original. Integrations aren't copied.

The channel endpoints change channel settings such as content type, flagging mode, and media settings. To change a channel's policies and rules, use the dashboard, or duplicate a channel that already has them.

## Roll a key

To replace a key without downtime, open the key's menu in **Settings → API keys** and click **Roll key**. The new key has the same access and lifetime as the old one. Choose when the old key stops working: **Now**, **1 hour**, **24 hours**, or **7 days**. The old key never outlives its own expiry date.

To revoke a key at once, click **Delete**.

## Activity and audit

Each key shows when it was last used. Every change made with an organization key shows in **Settings → Activity**, with the key that made it.

## Rate limits

The management API allows 60 requests per minute per organization, separate from your moderation [rate limit](/api-reference/rate-limits). When you create many projects in a script, handle `429` responses and retry after the time in the `Retry-After` header.

## Errors

| Status | Reason |
| - | - |
| `401` | The key is missing, invalid, or expired. |
| `403` | The key is a project key, the key doesn't have the permission the endpoint needs, or your plan doesn't include the management API. |
| `404` | The project or channel doesn't exist, or it's outside the key's project limit. |
| `429` | Too many requests. See [Rate limits](#rate-limits). |

The response's `message` says which case applies. See [Errors](/api-reference/errors) for the response format.
