/v1/keys/{id}Update an API key
keys:createChange a key permission set, its label, or whether it must sign every request, keeping the key id, its secrets, its credit cap, and its history. New entitlements must still be a subset of what you can grant, so an edit can never raise a key above your own scope. A scope change takes effect immediately, on the very next request the key makes, with no grace window. Turning on requireSignature needs a signer already registered on the key, so rotate with a publicKeyJwk first. Any omitted field is left unchanged.
Path parameters
idstring requiredmax 16 chars
Request body UpdateKeyRequest
entitlementsarray of stringReplace the key’s permission set. Re-checked against what you may grant, so an edit can never raise a key above your own scope. The change applies to the very next request the key makes, with no grace window.
max 38 itemslabelstringRename the key.
max 200 charsrequireSignaturebooleanTurn per-request signature enforcement on or off. Turning it ON requires a signer already registered on the key, so rotate with a `publicKeyJwk` first; otherwise this is a 400.
Responses
200The updated keyidstring requiredThe key id. Stable across rotations: rotating changes the secret, never the id.
labelstring requiredYour own name for the key.
credentialKindstring requiredWhat kind of credential this is.
statusstring requiredWhether the key is live or revoked.
requireSignatureboolean requiredWhen true, every request from this key must carry a valid RFC 9421 HTTP message signature; an unsigned request is rejected with a 401. Enforcement is per key, not global.
entitlementsarray of string requiredExactly what this key may do. Always a subset of what its creator could grant, so a key can never exceed the person or key that minted it. Changing it takes effect on the very next request, with no grace window.
createdByKindstring requiredWhether a member or another key created this one.
createdByIdstring requiredThe member id or key id that created it.
createdAtstring requiredWhen the key was created, as an ISO 8601 instant.
revokedAtstring | null requiredWhen the key was revoked, as an ISO 8601 instant. Null while live. Revocation is immediate and irreversible.
lastUsedAtstring | null requiredWhen the key was last seen on a request, as an ISO 8601 instant. Null means it has never been used, which is how you find keys safe to revoke.
secretsarray of KeySecretView requiredThe live secrets on this key, masked. Two are present during a rotation grace window.
prefixHintstring requiredThe leading, non-secret part of the key string, for recognising it.
last4string requiredThe last four characters, for distinguishing two keys at a glance.
displaystring requiredThe masked form to show a user. Safe to log and display; it is not the credential.
createdAtstring requiredWhen this secret was minted, as an ISO 8601 instant.
expiresAtstring | null requiredWhen this secret stops resolving, as an ISO 8601 instant. Set on a secret retired by a rotation, during its grace window. Null on the current secret.
creditCapinteger | null requiredA ceiling on what this key may spend per period. Null means uncapped. A key that hits its cap is refused with a 429 until the period rolls over, which contains a runaway agent without touching the rest of the account.
monthSpentinteger requiredCredits this key has spent in the current period, measured against `creditCap`.
400requireSignature with no registered signercodestring requiredStable machine-readable error code. Branch on this, never on the numeric status.
bad_requestunauthorizedsignature_requiredpayment_requiredforbiddennot_foundconflictgonepayload_too_largeunprocessable_entitytoo_many_requestsinternal_errornot_implementedbilling_unavailablenot_contactablemailbox_link_unavailablemailbox_requiredmail_engine_unavailablewebhook_publisher_unavailabledatabase_unavailableclient_errormessagestring requiredHuman-readable explanation of the refusal.
statusinteger requiredThe HTTP status code, repeated in the body.
remedyobjectA self-serve path forward, when one exists (a 402 points at the credit top-up).
kindstring requiredWhat kind of remedy this is, so a client can route it: whether the caller can clear the condition through the API, or a person must act in the web app.
topupconnect_mailboxurlstring requiredWhere to go to clear the condition: an API path, or a web app page when only a person can.
401No or invalid credentialcodestring requiredStable machine-readable error code. Branch on this, never on the numeric status.
bad_requestunauthorizedsignature_requiredpayment_requiredforbiddennot_foundconflictgonepayload_too_largeunprocessable_entitytoo_many_requestsinternal_errornot_implementedbilling_unavailablenot_contactablemailbox_link_unavailablemailbox_requiredmail_engine_unavailablewebhook_publisher_unavailabledatabase_unavailableclient_errormessagestring requiredHuman-readable explanation of the refusal.
statusinteger requiredThe HTTP status code, repeated in the body.
remedyobjectA self-serve path forward, when one exists (a 402 points at the credit top-up).
kindstring requiredWhat kind of remedy this is, so a client can route it: whether the caller can clear the condition through the API, or a person must act in the web app.
topupconnect_mailboxurlstring requiredWhere to go to clear the condition: an API path, or a web app page when only a person can.
402Plan does not include API keyscodestring requiredStable machine-readable error code. Branch on this, never on the numeric status.
bad_requestunauthorizedsignature_requiredpayment_requiredforbiddennot_foundconflictgonepayload_too_largeunprocessable_entitytoo_many_requestsinternal_errornot_implementedbilling_unavailablenot_contactablemailbox_link_unavailablemailbox_requiredmail_engine_unavailablewebhook_publisher_unavailabledatabase_unavailableclient_errormessagestring requiredHuman-readable explanation of the refusal.
statusinteger requiredThe HTTP status code, repeated in the body.
remedyobjectA self-serve path forward, when one exists (a 402 points at the credit top-up).
kindstring requiredWhat kind of remedy this is, so a client can route it: whether the caller can clear the condition through the API, or a person must act in the web app.
topupconnect_mailboxurlstring requiredWhere to go to clear the condition: an API path, or a web app page when only a person can.
403Missing keys:create, or entitlements you cannot grantcodestring requiredStable machine-readable error code. Branch on this, never on the numeric status.
bad_requestunauthorizedsignature_requiredpayment_requiredforbiddennot_foundconflictgonepayload_too_largeunprocessable_entitytoo_many_requestsinternal_errornot_implementedbilling_unavailablenot_contactablemailbox_link_unavailablemailbox_requiredmail_engine_unavailablewebhook_publisher_unavailabledatabase_unavailableclient_errormessagestring requiredHuman-readable explanation of the refusal.
statusinteger requiredThe HTTP status code, repeated in the body.
remedyobjectA self-serve path forward, when one exists (a 402 points at the credit top-up).
kindstring requiredWhat kind of remedy this is, so a client can route it: whether the caller can clear the condition through the API, or a person must act in the web app.
topupconnect_mailboxurlstring requiredWhere to go to clear the condition: an API path, or a web app page when only a person can.
404No such key on this accountcodestring requiredStable machine-readable error code. Branch on this, never on the numeric status.
bad_requestunauthorizedsignature_requiredpayment_requiredforbiddennot_foundconflictgonepayload_too_largeunprocessable_entitytoo_many_requestsinternal_errornot_implementedbilling_unavailablenot_contactablemailbox_link_unavailablemailbox_requiredmail_engine_unavailablewebhook_publisher_unavailabledatabase_unavailableclient_errormessagestring requiredHuman-readable explanation of the refusal.
statusinteger requiredThe HTTP status code, repeated in the body.
remedyobjectA self-serve path forward, when one exists (a 402 points at the credit top-up).
kindstring requiredWhat kind of remedy this is, so a client can route it: whether the caller can clear the condition through the API, or a person must act in the web app.
topupconnect_mailboxurlstring requiredWhere to go to clear the condition: an API path, or a web app page when only a person can.