Cumulus TalosDocs
Open Talos
On this page

keys.rotate

Replace an API key's secret

Request

POST /api/v1/keys/{key_id}/rotate

  • MCP: keys_rotate
  • SDK: client.keys.rotate (SDK path arguments use path; MCP uses params).
  • Minimum API key role: admin.
  • Idempotency: required_header. Send an Idempotency-Key header; MCP uses idempotency_key. Reuse it after an unknown outcome.

Use the request schema below. Read IDs from earlier operation results.

Input schema

json
{
  "parameters": [
    {
      "name": "key_id",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string",
        "format": "uuid"
      }
    },
    {
      "name": "Idempotency-Key",
      "in": "header",
      "required": true,
      "schema": {
        "type": "string",
        "minLength": 1,
        "maxLength": 256
      }
    }
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/KeysRotateRequest"
        }
      }
    }
  }
}

Responses

json
{
  "201": {
    "description": "Replace an API key's secret",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ApiKeyCreated"
        }
      }
    }
  },
  "4XX": {
    "description": "Typed error (ApiError)",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ApiError"
        }
      }
    }
  },
  "5XX": {
    "description": "Typed error (ApiError)",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ApiError"
        }
      }
    }
  }
}

Referenced schemas

json
{
  "components": {
    "schemas": {
      "KeysRotateRequest": {
        "type": "object",
        "properties": {},
        "additionalProperties": false
      },
      "ApiKeyCreated": {
        "type": "object",
        "properties": {
          "key_id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "role": {
            "type": "string",
            "enum": [
              "admin",
              "member",
              "viewer"
            ]
          },
          "can_dial": {
            "type": "boolean"
          },
          "prefix": {
            "type": "string",
            "minLength": 4,
            "maxLength": 32
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "last_used_at": {
            "allOf": [
              {
                "type": "string",
                "format": "date-time"
              }
            ],
            "nullable": true
          },
          "expires_at": {
            "allOf": [
              {
                "type": "string",
                "format": "date-time"
              }
            ],
            "nullable": true
          },
          "revoked_at": {
            "allOf": [
              {
                "type": "string",
                "format": "date-time"
              }
            ],
            "nullable": true
          },
          "secret": {
            "type": "string",
            "minLength": 16,
            "maxLength": 256
          }
        },
        "required": [
          "key_id",
          "name",
          "role",
          "can_dial",
          "prefix",
          "created_at",
          "last_used_at",
          "expires_at",
          "revoked_at",
          "secret"
        ],
        "additionalProperties": false
      },
      "ApiError": {
        "type": "object",
        "properties": {
          "error": {
            "type": "object",
            "properties": {
              "code": {
                "type": "string",
                "enum": [
                  "unauthenticated",
                  "forbidden",
                  "not_found",
                  "conflict",
                  "invalid_request",
                  "idempotency_conflict",
                  "policy_denied",
                  "capability_unavailable",
                  "provider_unavailable",
                  "knowledge_unavailable",
                  "publication_invalid",
                  "run_not_active",
                  "rate_limited",
                  "outcome_unknown",
                  "internal"
                ]
              },
              "message": {
                "type": "string"
              },
              "retryable": {
                "type": "boolean"
              },
              "outcome": {
                "type": "string",
                "enum": [
                  "none",
                  "unknown"
                ]
              },
              "details": {
                "type": "object",
                "additionalProperties": {}
              }
            },
            "required": [
              "code",
              "message",
              "retryable",
              "outcome"
            ],
            "additionalProperties": false
          }
        },
        "required": [
          "error"
        ],
        "additionalProperties": false
      }
    }
  }
}

Errors and recovery

See API error handling and Troubleshooting.

Content version bbbf8d2eMarkdown source
keys.rotate · Cumulus Talos docs