> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mixlayer.com/api-reference/platform-api/api-key-management/rotate-api-key/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mixlayer.com/_mcp/server. # Rotate an API key secret POST https://api.mixlayer.com/v1/organizations/{org_id}/api_keys/{key_id}/rotate When authenticated with an API key, this operation requires `api-admin`. Reference: https://docs.mixlayer.com/api-reference/platform-api/api-key-management/rotate-api-key ## Authentication - `Authorization` header (bearer token, required) — Console user session or Mixlayer API key supplied as a Bearer token. ## Request ### Path parameters - `org_id` (string, required) — Organization ID - `key_id` (string, required) — API key ID ## Response ### 200 Rotated API key and its one-time secret - `data` (ApiDataResponseApiKeyWithSecretResponseData, required) — User-facing API key metadata with its one-time secret. ## Errors ### 401 Unauthorized Error Authentication is missing or invalid. - `error` (ApiErrorBody, required) — Structured error details. ### 403 Forbidden Error The authenticated principal cannot perform this operation. - `error` (ApiErrorBody, required) — Structured error details. ### 404 Not Found Error API key not found - `error` (ApiErrorBody, required) — Structured error details. ### 500 Internal Server Error An unexpected server or database error occurred. - `error` (ApiErrorBody, required) — Structured error details. ## Types ### ApiDataResponseApiKeyWithSecretResponseData User-facing API key metadata with its one-time secret. - `active` (boolean, required) — Whether the key can currently authenticate requests. - `created_at` (datetime, required) — Time the key was created. - `id` (string, required) — Stable API key identifier. - `name` (string, required) — Human-readable API key name. - `permissions` (list of enum, required) — Permission scopes granted to the key. - Allowed values: `inference`, `api-read`, `api-write`, `api-admin` - `key` (string, required) — One-time API key secret. This value is not returned again. - `expires_at` (datetime, optional, nullable) — Time the key expires, or null when it does not expire. ### ApiErrorBody Structured error details returned by the platform API. - `message` (string, required) — Human-readable error message. - `code` (string, optional, nullable) — Stable machine-readable error code, when available. - `details` (any, optional) — Error-specific structured context, when available. ## Examples **Response** ```json { "data": { "active": true, "created_at": "2024-01-15T09:30:00Z", "id": "string", "name": "string", "permissions": [ "inference" ], "key": "string", "expires_at": null } } ``` **SDK Code** ```python import requests url = "https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate" headers = {"Authorization": "Bearer "} response = requests.post(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate'; const options = {method: 'POST', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate" req, _ := http.NewRequest("POST", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate") .header("Authorization", "Bearer ") .asString(); ``` ```php request('POST', 'https://api.mixlayer.com/v1/organizations/org_id/api_keys/key_id/rotate', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ```