🤖 For AI agents: The complete documentation index is available at /docs/llms.txt. A markdown version of this page is available at /docs/apis/api-keys/update-an-api-key.md.

Update an API Key

This API is used to update an existing API Key. A tenant-scoped API key can update another API key for the same tenant.

API Key Authentication
Update the Key with the given Id
PUT/api/api-key/{keyId}
OpenAPI Spec

Request#

Request Parameters#

apiKeyId UUID required

The unique Id of the API Key to update.

Request Body#

apiKey.expirationInstant Long optional Available since 1.55.0

The expiration instant of this API key. Using an expired API key for API Authentication will result in a 401 response code.

Note that omitting this field or providing a null value will clear the expiration instant of this API key.
apiKey.key String optional

API key string. When you create an API key the key is defaulted to a secure random value but the API key is simply a string, so you may call it super-secret-key if you'd like. However a long and random value makes a good API key in that it is unique and difficult to guess.

apiKey.ipAccessControlListId UUID optional Available since 1.30.0

The Id of the IP Access Control List limiting access to this API key.

Note: To use , you'll need an Enterprise plan.

apiKey.metaData.attributes.description String optional

Description of the key.

apiKey.name String optional Available since 1.56.0

The name of the API key. Must be unique.

If apiKey.retrievable is false then this field is required.

apiKey.permissions.endpoints Object optional

Endpoint permissions for this key. Each key of the object is an endpoint, with the value being an array of the HTTP methods which can be used against the endpoint. An Empty permissions object mean that this is a super key that authorizes this key for all the endpoints.

apiKey.retrievable Boolean optional Defaults to true Available since 1.56.0

Indicates whether this key is retrievable. If this value is false, the key will not be returned in the API response.

This value is read-only once the key is created. If this value is set to false then the apiKey.name field is required.

apiKey.tenantId String optional

The unique Id of the Tenant. This value is required if the key is meant to be tenant scoped. Tenant scoped keys can only be used to access users and other tenant scoped objects for the specified tenant. This value is read-only once the key is created.

Tenant-scoped keys have read-only access to entities that are shared between tenants. You can further limit these API keys by specifying required endpoints, permissions, and a tenant.

Example API Key request JSON

{
  "apiKey": {
    "expirationInstant": 1878422400000,
    "ipAccessControlListId": "eae37b0e-950b-4e92-abcc-d0b310326f66",
    "metaData": {
      "attributes": {
        "description": "updating the key"
      }
    },
    "name": "Another Awesome API Key",
    "permissions": {
      "endpoints": {
        "/api/application": [
          "DELETE",
          "POST",
          "GET",
          "PUT",
          "PATCH"
        ]
      }
    }
  }
}

Response#

The response for this API contains the Key that was updated.

Response Codes
CodeDescription
200The request was successful. The response will contain a JSON body.
400The request was invalid and/or malformed. The response will contain an Errors JSON Object with the specific errors. This status will also be returned if a paid FusionAuth license is required and is not present.
401You did not supply a valid Authorization header. The header was omitted or your API key was not valid. The response will be empty. See Authentication.
404The object you are trying to update doesn't exist. The response will be empty.
500There was an internal error. A stack trace is provided and logged in the FusionAuth log files. The response will be empty.

Response Body#

apiKey.expirationInstant Long Available since 1.55.0

The expiration instant of this API key. Using an expired API key for API Authentication will result in a 401 response code.

apiKey.id UUID

The Id of the API key.

apiKey.id UUID

The Id of the API key.

apiKey.insertInstant Long

The instant when the API key was added to the FusionAuth database.

apiKey.ipAccessControlListId UUID Available since 1.30.0

The Id of the IP Access Control List limiting access to this API key.

apiKey.key String

The API key value, this is the string value you will use in the Authorization header to authenticate API requests.

If the apiKey.retrievable value is false then this will be the only time the key is returned in the response.

apiKey.key String

The API key value. This is the string value you will use in the Authorization header to authenticate API requests.

If the apiKey.retrievable value is false then this field will not be returned in the response.

apiKey.keyManager Boolean

Indicates whether this key is a key manager. Setting this flag to true allows this key to be used to call these APIs. An attempt to call these APIs with a non-manager key (keyManager set to false) will always return a HTTP response status code 401.

apiKey.lastUpdateInstant Long

The instant when the API key was last updated in the FusionAuth database.

apiKey.metaData.attributes.description String

Description of the key.

apiKey.name String Available since 1.56.0

The name of the API key.

apiKey.permissions.endpoints Object

Endpoint permissions for this key. Each key of the object is an endpoint, with the value being an array of the HTTP methods which can be used against the endpoint. An empty permissions object mean that this is a super key that authorizes this key for all the endpoints.

apiKey.retrievable Boolean Available since 1.56.0

Indicates whether this key is retrievable.

If this value is false, the apiKey.key will not be returned in the API response.

apiKey.tenantId String

The unique Id of the Tenant. This value is read-only once the key is created.

Example API Key Response JSON

{
  "apiKey": {
    "expirationInstant": 1878422400000,
    "id": "b016fa93-e8bc-4b79-b39f-5d37966c0178",
    "insertInstant": 1619119404194,
    "ipAccessControlListId": "eae37b0e-950b-4e92-abcc-d0b310326f66",
    "key": "WHYugARKzum-jHvzCk5-C558EKPaYEECz5k8fDZayIaFiZHRKqy9kaQn",
    "keyManager": false,
    "lastUpdateInstant": 1619121061858,
    "metaData": {
      "attributes": {
        "description": "updating the key"
      }
    },
    "name": "Another Awesome API Key",
    "permissions": {
      "endpoints": {
        "/api/application": [
          "DELETE",
          "POST",
          "GET",
          "PUT",
          "PATCH"
        ]
      }
    },
    "retrievable": true,
    "tenantId": "94f751c5-4883-4684-a817-6b106778edec"
  }
}