# Generate User Api Key Without User Approval

**URL:** <https://meta.discourse.org/t/generate-user-api-key-without-user-approval/310210>\
**Category:** Development\
**Created:** [June 1, 2024, 7:30pm UTC](https://meta.discourse.org/t/generate-user-api-key-without-user-approval/310210 "2024-06-01T19:30:32Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![BrainFried](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/brainfried/32/388499_2.png) [@BrainFried](https://meta.discourse.org/u/BrainFried)\
**Post date:** [June 1, 2024, 7:30pm UTC](https://meta.discourse.org/t/generate-user-api-key-without-user-approval/310210/1 "2024-06-01T19:30:32Z")

</div>

I’m using Discourse headless, and I’m able to get User information using the Admin API key, but it was recommended to instead generate a user API for each user. So I’m trying to do that method instead but I don’t want the User to have to navigate to a new UI to “approve” the API that I’m creating for them.

So, my solution is to programmatically submit the confirmation. From a GET request to ‘/user-api-key/new’, I’m able to parse out the ‘form’ element data but I can’t send a POST request to '/user-api-key/'because I’ll get a CSRF error.

I’ve disabled CSRF protection for [discourse connect](https://meta.discourse.org/t/13045?silent=true), but is there another one for api-key?  
SiteSetting.discourse\_connect\_csrf\_protection

If not, I won’t be using the User API keys until I’m able to create them without the UI interruption.

Thanks in advance!

Apparently, one solution that could work use to exist in previous versions but I’m not seeing any updated version of this:

> [@How to programmatically generate user api key](https://meta.discourse.org/t/how-to-programmatically-generate-user-api-key/151738/3):
>
> Hi According with the docs it may be possible to create an user api key from an admin user via the rest API [generate api key for a user from an admin user](https://docs.discourse.org/#tag/Admin/paths/~1admin~1api~1keys/post) In previous versions it worked as “admin/users/‘+ user\_id +’/generate\_api\_key”. I don’t know why in latest version it changes. Thank you for your help

---

_[View the full topic](https://meta.discourse.org/t/generate-user-api-key-without-user-approval/310210)._
