API keys
Rotate an API key
Creates a new key with the same name, scope and IP allowlist and returns it with its secret key, shown once. The old key keeps working for grace_hours, then is revoked automatically. For a blocked key the old key stops at once (grace_hours is ignored). Recorded in the audit log as api_key.rotated.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Path parameters
iduuidrequiredKey id (not the key itself).
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Body
application/jsongrace_hoursintegeroptionalHow long the old key keeps working, so you can deploy the new key first.
0stops it now. Always0for a key blocked as leaked.
Response
201 Createdapplication/json
iduuidKey id. Use it to delete the key.
namestringName you gave the key.
prefixstringFirst 16 characters of the key (for example
pk_live_3f9a1c0b), so you can recognise it.scopeenumread(GET requests only),write(every request an API key may make) oradmin(writeplus the security and audit endpoints).created_atintegerCreation time in Unix seconds.
expires_atintegerExpiry time in Unix seconds (30, 90 or 365 days after creation, as chosen);
0when the key never expires.revokedinteger1once the key has been deleted (revoked), otherwise0.statusenumactive,blocked_leaked(blocked because it may have been leaked),revokedorexpired. A blocked key that was also revoked showsblocked_leaked.blocked_atintegerWhen the key was blocked, in Unix seconds;
0if it is not blocked.blocked_reasonstringWhy it was blocked, for example
found in a public GitHub location https://github.com/…,reported as leakedorused from 3 countries within an hour (SI, US, BR);""if it is not blocked.blocked_byenumWhat blocked it:
github(GitHub secret scanning),report(a public report),behaviour(unusual use) oradmin;""if it is not blocked.replaced_byuuidId of the key that replaced this one;
""if it was not replaced.revoke_atintegerFor a rotated key: when it stops working and is revoked automatically, in Unix seconds;
0if nothing is scheduled.allowed_ipsarray<string>IP addresses and CIDR ranges the key may be used from. An empty array means any address.
last_used_atintegerWhen the key was last used, in Unix seconds;
0if it was never used. Updated at most once a minute, or sooner when the address changes.last_used_ipstringIP address of the last request made with the key;
""if it was never used.keystringmay be absentThe full secret key. Returned only in the create and rotate responses.
replacesuuidId of the old key.
old_key_revoke_atintegerWhen the old key stops working, in Unix seconds;
0when it stopped at once (grace_hours: 0, or a blocked key).
Status codes
- 201Created. The new key, including the secret
key, plus the id of the key it replaces and when that one stops working. - 400Bad request.
grace_hoursis not a whole number from 0 to 72, or the id is not a valid UUID. - 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden. - 404Not found. No key with this id in the workspace.
- 409Conflict. The key was already rotated or replaced (
code: "api_key_already_replaced"). Use the key in itsreplaced_by.