Skip to main content
POST
Rotate an API key

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id
string
required

an API key ID: key_ and 32 lowercase hex digits

Example:

"key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

Body

application/json
deliver
enum<string>

Answer a Dashboard link instead of the secret, so the secret never reaches this client

Available options:
dashboard

Response

The key and its new one-time secret; With deliver dashboard: where to finish

id
string
required

an API key ID: key_ and 32 lowercase hex digits

Example:

"key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

name
string
required
Example:

"Nightly price check"

permissions
enum<string>[]
required
Available options:
tools:read,
usage:read,
tools:build,
runs:create,
jobs:read,
jobs:cancel,
connections:read,
credentials:manage,
api_keys:manage
Example:
integration_id
string | null
required

The one integration the key is bound to, or null for an account key

Example:

"int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

prefix
string
required

The token's visible start, pom_ and 8 hex digits, to tell keys apart

Example:

"pom_0f8e2d1c"

created_via
enum<string>
required

Where the key was created

Available options:
dashboard,
api,
mcp
created_at
string<date-time>
required

An ISO 8601 timestamp in UTC

Example:

"2026-10-05T18:30:00.000Z"

expires_at
string<date-time>
required

An ISO 8601 timestamp in UTC

Example:

"2026-10-05T18:30:00.000Z"

last_used_at
string<date-time> | null
required

When a request last used the key, or null if none has

Example:

"2026-10-05T18:30:00.000Z"

secret
string
required

The key's secret, shown in this answer only. Send it as a Bearer token.

Example:

"pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000"