Skip to main content
POST
Confirm your deployment before running this request. This page describes an API contract; a published reference does not establish hosted availability. Check the dated host report and obtain your deployment URL and credentials. Replace the example host if your provisioned service uses a different URL.
Issue a new plaintext secret for an existing key, in place. Preserves the row’s id, name, scopes, rate limit, and expiration — only the secret (and therefore key_hash + key_prefix) changes. The old plaintext stops working the instant this commits, so callers should orchestrate the cutover: deploy the new value before calling rotate, OR have a brief outage if you can tolerate it. A key can rotate itself; the response carries the new plaintext, but the caller must update their auth header on the next request.

Path parameters

string (uuid)
required

Request body

No request body.

Response

CreateAPIKeyResponse
string
required
string
required
string
required
Plaintext API key — store it now. The platform only retains the SHA-256 hash; this is the one and only time the secret is exposed.
string
required
string[]
required
integer
required
string
required

Status codes

Using this contract

Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.
Last modified on September 21, 2026