curl --request POST \
--url https://api.pomerado.ai/v1/api-keys/{id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"deliver": "dashboard"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({deliver: 'dashboard'})
};
fetch('https://api.pomerado.ai/v1/api-keys/{id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/api-keys/{id}/rotate"
payload = { "deliver": "dashboard" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"name": "Nightly price check",
"permissions": [
"tools:read",
"runs:create",
"jobs:read"
],
"integration_id": "int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"prefix": "pom_0f8e2d1c",
"created_via": "dashboard",
"created_at": "2026-10-05T18:30:00.000Z",
"expires_at": "2026-10-05T18:30:00.000Z",
"last_used_at": "2026-10-05T18:30:00.000Z",
"secret": "pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Rotate an API key
Replace a key’s secret and return the new one once. The old secret stops working at once; the key keeps its ID, permissions, expiry and running jobs. With deliver “dashboard”, nothing changes yet: the answer is a Dashboard link where the person rotates the key and sees the new secret. Only a key whose permissions the caller holds itself can be rotated.
curl --request POST \
--url https://api.pomerado.ai/v1/api-keys/{id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"deliver": "dashboard"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({deliver: 'dashboard'})
};
fetch('https://api.pomerado.ai/v1/api-keys/{id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/api-keys/{id}/rotate"
payload = { "deliver": "dashboard" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"name": "Nightly price check",
"permissions": [
"tools:read",
"runs:create",
"jobs:read"
],
"integration_id": "int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"prefix": "pom_0f8e2d1c",
"created_via": "dashboard",
"created_at": "2026-10-05T18:30:00.000Z",
"expires_at": "2026-10-05T18:30:00.000Z",
"last_used_at": "2026-10-05T18:30:00.000Z",
"secret": "pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
an API key ID: key_ and 32 lowercase hex digits
"key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Body
Answer a Dashboard link instead of the secret, so the secret never reaches this client
dashboard Response
The key and its new one-time secret; With deliver dashboard: where to finish
- Option 1
- Option 2
an API key ID: key_ and 32 lowercase hex digits
"key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
"Nightly price check"
tools:read, usage:read, tools:build, runs:create, jobs:read, jobs:cancel, connections:read, credentials:manage, api_keys:manage ["tools:read", "runs:create", "jobs:read"]
The one integration the key is bound to, or null for an account key
"int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
The token's visible start, pom_ and 8 hex digits, to tell keys apart
"pom_0f8e2d1c"
Where the key was created
dashboard, api, mcp An ISO 8601 timestamp in UTC
"2026-10-05T18:30:00.000Z"
An ISO 8601 timestamp in UTC
"2026-10-05T18:30:00.000Z"
When a request last used the key, or null if none has
"2026-10-05T18:30:00.000Z"
The key's secret, shown in this answer only. Send it as a Bearer token.
"pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000"