Skip to main content
PATCH
Change an API key
Requires an ADMIN key. An API key gets 403 with code: insufficient_permissions — see API Keys.
Disable or re-enable an API key, or change its expiration date, spend limit, reset window or IP allowlist. Send only the fields you want to change. The role cannot be changed, and ADMIN keys can be changed only in the Dashboard. Changes apply from the next request. Changing the spend limit does not reset the counter; changing the reset window does.

Authorizations

Authorization
string
header
required

Sanctum personal access token, sent as Authorization: Bearer <token>. The token is opaque — it carries no claims and no embedded expiry, so do not attempt to decode it. Issue and revoke tokens from your account dashboard.

Headers

Accept
enum<string>
default:application/json
required
Available options:
application/json

Path Parameters

id
integer
required

Body

application/json
active
boolean

false disables the key, true enables it again.

Example:

false

expires_at
string<date-time> | null

null removes the expiry date. A date must be in the future and no later than 2038-01-19 03:14:07 UTC, the latest instant this platform can store — a 422, not a silently shortened key.

Example:

"2027-01-31T23:59:59Z"

ip_whitelist
string[]

Replaces the whole list — entries are not merged with the ones already there. [] clears it and the key works from any address again; omitting the field leaves the list untouched, and an explicit null is refused.

Maximum array length: 20
Example:
limit
number<float> | null

The new spend limit per window, in USD. null removes the limit; omitting the field leaves both the limit and what has been spent against it untouched. Changing the amount never resets the counter: raising it from 50 to 100 on a key that has already spent 50 leaves 50 of room, and lowering it below what has been spent accepts nothing more until the window resets.

Required range: 0 <= x <= 999999.999999
Example:

100

reset_interval
enum<string>

The new window. Changing it restarts the counter. Can be sent on its own, but only for a key that already has a limit; alongside "limit": null it is refused.

Available options:
none,
daily,
weekly,
monthly
Example:

"daily"

Response

The key after the change.

data
object