Revoke an API key
POST/api-keys/:id/rotate
Permanently disables the API key. Any subsequent request presenting the plaintext returns 401. Emits api_key.revoke audit event. Requires the api-key:write permission.
Request
Responses
- 200
- 201
- 204
- 400
- 401
- 403
- 404
- 429
- 500
New plaintext secret (returned ONCE) + row metadata.
Resource created. Body follows the shared { data, meta } envelope; data is the newly-created resource.
Key revoked; no response body.
The request payload failed validation. error.details lists the offending fields with human-readable messages and the class-validator constraint that fired. Fix the payload and retry — this is not a transient failure.
Missing or invalid access token.
Caller lacks the required permission.
ApiKey not found.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.