Revoke API Key
Immediately disables an API key without deleting its record — `isActive` becomes false and `revokedAt` is stamped. The cached authentication record is purged at the same time, so the secret stops working right away rather than after the cache expires. A revoked key cannot be reactivated; rotate or create a new one instead. `data` is `null` on success.
Internal session cookie for local development.
In: cookie
Path Parameters
The ID of the API key to revoke.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/api/v1/api-keys/string/revoke"{ "success": true, "message": "API key revoked successfully", "data": null}Rotate API KeyPOST
Revokes the target key and issues a replacement in one transaction. The old secret stops working immediately. Every field in the body is optional — send `{}` to rotate the secret while carrying over the existing name, scopes, and rate limit. As with creation, the new secret is returned exactly once. The response also carries `rotatedFromId`, the id of the key that was replaced. Only an active, unrevoked key can be rotated; anything else returns `404`.
Delete API KeyDELETE
Permanently removes an API key and its record. Use `POST /api-keys/{id}/revoke` instead if you want to keep the audit trail. `data` is `null` on success.