Administration

api_keys.rotate

Replace your API key while preserving scope ceilings and revoking the original.

POST/api/v1/accounting/api_keys.rotate

Permissions

api_keys:manage

Who can call it

admin, finance, contributor

Retries

Idempotency key required, with expectedRevision

MCP

accounting_api_keys_rotate

Can't be undone

It deletes, voids, revokes or discards something. Confirm with a person first.

Fields

  • idstring (ID)Required

    The record's ID.

  • expectedRevisionintegerRequired

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    at most 9007199254740991 · greater than 0

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–160 characters

  • namestring

    A display name.

    1–100 characters · Matches ^[^\u0000-\u001f\u007f]+$

  • scopesarray of enum values

    What the API key may do. A key can never do more than the person who made it.

    accounting:readaccounting:writeaccounting:adminmail:readmail:writemail:securityapi_keys:managemailboxes:search

    1–8 items

  • expiresAtstring (date-time)

    When this stops working, as an ISO 8601 date and time.

Example

curl https://app.getoatmilk.com/api/v1/accounting/api_keys.rotate \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/api_keys.rotate
curl https://app.getoatmilk.com/api/v1/accounting/api_keys.rotate \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3
}'

More in Administration.