Rotate an API key's secret
Replace the key's secret in place, keeping its id, name and scopes. The PREVIOUS secret stops authenticating immediately — there is no overlap window — so anything still using it starts failing on its next request. As with creation, the new secret is not returned: the response carries lastFour and a one-time revealUrl. A revoked key cannot be rotated (400 KEY_REVOKED).
Requires the api-keys:write scope — Create, rotate, and revoke API keys — these keep working even after you disconnect this app.
BetterAuth session cookie. Used by the dashboard / browser clients. When present, the active project is taken from the x-project-id header.
In: cookie
Path Parameters
Project id.
API key id.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/projects/string/api-keys/string/rotate"{
"success": true,
"data": {
"lastFour": "string",
"revealUrl": "http://example.com",
"revealExpiresAt": "2019-08-24T14:15:22Z"
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}{
"success": false,
"error": {
"message": "string",
"code": "string",
"details": {
"errors": [
null
]
}
}
}