A new secret for the same key; the old one stops working at once. The expiry is kept. Only the key's creator may rotate it; an expired key is 404.
Authenticate with a signed-in session token (an API key cannot call this route).
Path parameters
The org's slug or id. A caller with no role in the org gets 404.
The key's id (key_…), not its secret.
Responses
200The key, with its new secret.
key_…; use it in the key routes.
The secret's first characters, to tell keys apart.
2 fields
The key's secret. Only in the create and rotate responses; never shown again.
The webhook signing secret. Only in the update response that minted it.
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
404No such resource for the caller, including one that exists in an org the caller cannot see.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.