Skip to content
View as Markdown

Rotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an exp...

POST/v1/abilities/key.rotate

Rotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an expiry — default 24h overlap — so consumers can be moved without an outage. Admin, or the key’s own tenant. Auth-required.

Required
Yes
Content type
  • application/json
  • inputKeyRotateInputrequired
    Show 2 properties
    • idstringrequired

      Key id (key_…) from key.list.

    • overlapHoursnumberoptional

      How long the OLD key keeps working. 0..336, default 24.

  • contextCallContextoptional

    Optional call context. The tenant always comes from the credential: tenantId is honoured only by a credential allowed to address sub-tenants, and then nests under the credential’s own tenant.

    Show 3 properties
    • tenantIdstringoptional

      Sub-tenant to act for (sub-tenant credentials only).

    • runIdstringoptional

      The trust run (from trust.preflight) this call executes under.

    • verticalIdstringoptional

      Vertical to attribute created records to.

Schema shown for 200 · application/json

  • result

    The ability’s return value. Its shape depends on the ability.