Skip to main content
POST
Rotate API key

Authorizations

sb-access-token
string
cookie
required

The signed-in browser session (Google or Apple). Used only for key management, same-origin JSON requests only. An API key presented here is refused (401 session_required).

Path Parameters

id
string<uuid>
required

Body

application/json
graceSeconds
integer
default:0

How long the old key keeps working. 0 revokes it at once.

Required range: 0 <= x <= 86400
expiresInDays
integer

The new key's life. Omitted: the same life as the old key (at most 365 days), or none when the old key had none.

Required range: 1 <= x <= 365

Response

Rotated.

key
object
required
token
string
required

The new plaintext key. Shown once; only its hash is stored.

warning
string
required
replaced
object
required