Rotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an exp...
/v1/abilities/key.rotateRotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an expiry — default 24h overlap — so consumers can be moved without an outage. Admin, or the key’s own tenant. Auth-required.
Request body
Section titled “Request body”inputKeyRotateInputrequiredShow 2 properties
idstringrequiredKey id (key_…) from key.list.
overlapHoursnumberoptionalHow long the OLD key keeps working. 0..336, default 24.
contextCallContextoptionalOptional call context. The tenant always comes from the credential:
tenantIdis honoured only by a credential allowed to address sub-tenants, and then nests under the credential’s own tenant.Show 3 properties
tenantIdstringoptionalSub-tenant to act for (sub-tenant credentials only).
runIdstringoptionalThe trust run (from trust.preflight) this call executes under.
verticalIdstringoptionalVertical to attribute created records to.
Returns
Section titled “Returns”Schema shown for 200 · application/json
resultThe ability’s return value. Its shape depends on the ability.