Rotate Org API Key
Rotate an API key. Regenerates the token on the same role. The new raw key is shown only once.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Response
Key rotated. The new raw key is shown only once.
Returned on create/rotate — raw key shown only once
Internal role ID
Unique slug identifying the API key within the org
The raw API key (iak_{orgSlug}_{uuid}). Shown only once.
Array of permission strings. Convention: {product}:{resource}:{action} Wildcards: Use * at end only (e.g., orgs:* matches orgs:members:manage) Platform permissions: - orgs:* (full org access) - orgs:members:manage, orgs:roles:manage, orgs:manage - orgs:branding:manage, orgs:navigation:manage - orgs:subscriptions:view, orgs:subscriptions:manage - orgs:apikeys:manage, orgs:invites:manage, orgs:join-rules:manage - secure-chat:, store:, knowledge:, builder: - agent-builder:, analytics:view, platform-admin: Custom app permissions: {app-slug}:{resource}:{action} Example: my-crm:contacts:read, my-crm:deals:manage Super admin: ["*"] (matches everything)
Owner type (e.g. agent, vector_stores). Force-prefixed by the runtime when minted via access-manager.