Rotate API key
Replace an API key’s secret now. The new secret is returned in secret, only in this response. Send expiresAt to change the key’s expiry (null for never); omit it to keep the current one. The previous secret keeps authenticating for gracePeriodHours (default 0, so it stops working immediately), and never past expiresAt. The key keeps its id and name. Expired keys cannot be rotated. Only one previous secret is kept, so rotating again during a grace period retires the older one immediately.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your workspace API key. See Find your API key for more information.
Path Parameters
The workspace id.
The API key id.
Body
Response
The rotated key, with the new secret in secureKey.
The API key id.
The API key creation date.
The API key last update date.
The API key last use date.
An obfuscated hint of the API key value. When a key is created or rotated this also holds the full secret, for backward compatibility; prefer secret.
120"sk-o...5PW0"
The key's lifecycle state. active: the current secret authenticates. rotating: the key was rotated and the previous secret still authenticates until previousKeyExpiresAt. expired: expiresAt has passed and no secret authenticates.
active, rotating, expired "active"
The API key name.
120"Secret Key"
The full API key. Only present in the response that creates or rotates the key, and never shown again.
"sk-ol-Xq3v9Rk2mPz8TnW4yL7bC1dF5hJ6"
When the key stops authenticating. null means the key never expires. Set when the key is created or rotated, and must be in the future. When the request is authenticated with an API key that expires, the result can't be later than that key's expiry.
"2027-01-01T00:00:00Z"
When the key was last rotated.
While status is rotating, when the previous secret stops authenticating.