| Name | Type | Description | Notes |
|---|---|---|---|
| description | String | Human-readable label, e.g. the name of the tenant the key is for. | |
| active | Boolean | Whether the key can authenticate. Defaults to true. | [optional] |
| permissions | Permissions | [optional] | |
| companyIds | [Number] | Companies the key can access. When omitted or empty, the key can access all the companies of the account, including the ones created later. | [optional] |
| corsOrigins | [String] | Browser origins allowed to call the API with this key (CORS), e.g. `https://app.example.com` or `*.example.com`. A key used from a browser is public: keep its permissions and companies minimal. | [optional] |
| id | Number | Id of the restricted key to update. | [optional] |
| version | Number | Row version read with the key, for optimistic concurrency: a stale version fails with 422. | [optional] |