API keys
Update a key’s IP allowlist
Replaces the key’s allowed_ips and returns the key. Send an empty array to allow any address again. Only the allowlist can be changed: for another name or scope, create a new key. Recorded in the audit log as api_key.updated.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Path parameters
iduuidrequiredKey id (not the key itself).
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Body
application/jsonallowed_ipsarray<string>requiredIP addresses (
203.0.113.10,2001:db8::1) and CIDR ranges (198.51.100.0/24) the key may be used from. Requests from any other address get403withcode: "ip_not_allowed". An empty array (or leaving it out) allows any address.
Response
200 OKapplication/json
iduuidKey id. Use it to delete the key.
namestringName you gave the key.
prefixstringFirst 16 characters of the key (for example
pk_live_3f9a1c0b), so you can recognise it.scopeenumread(GET requests only),write(every request an API key may make) oradmin(writeplus the security and audit endpoints).created_atintegerCreation time in Unix seconds.
expires_atintegerExpiry time in Unix seconds (365 days after creation).
revokedinteger1once the key has been deleted (revoked), otherwise0.allowed_ipsarray<string>IP addresses and CIDR ranges the key may be used from. An empty array means any address.
last_used_atintegerWhen the key was last used, in Unix seconds;
0if it was never used. Updated at most once a minute, or sooner when the address changes.last_used_ipstringIP address of the last request made with the key;
""if it was never used.
Status codes
- 200OK. The key with its new
allowed_ips. The secret is not included. - 400Bad request.
allowed_ips entry 2 is not a valid IP address or CIDR range,allowed_ips can hold at most 20 entries,send allowed_ips (a list of IP addresses or CIDR ranges)orinvalid key id. - 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden. - 404Not found. No active key with this id in the workspace (a revoked key cannot be changed).
- 500Server error. The key could not be updated.