curl --request PATCH \
--url https://api.deapi.ai/api/v2/keys/{id} \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"active": false,
"expires_at": "2027-01-31T23:59:59Z",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"limit": 100,
"reset_interval": "daily"
}
'import requests
url = "https://api.deapi.ai/api/v2/keys/{id}"
payload = {
"active": False,
"expires_at": "2027-01-31T23:59:59Z",
"ip_whitelist": ["203.0.113.7", "198.51.100.0/24"],
"limit": 100,
"reset_interval": "daily"
}
headers = {
"Accept": "<accept>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
Accept: '<accept>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
active: false,
expires_at: '2027-01-31T23:59:59Z',
ip_whitelist: ['203.0.113.7', '198.51.100.0/24'],
limit: 100,
reset_interval: 'daily'
})
};
fetch('https://api.deapi.ai/api/v2/keys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.deapi.ai/api/v2/keys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'active' => false,
'expires_at' => '2027-01-31T23:59:59Z',
'ip_whitelist' => [
'203.0.113.7',
'198.51.100.0/24'
],
'limit' => 100,
'reset_interval' => 'daily'
]),
CURLOPT_HTTPHEADER => [
"Accept: <accept>",
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.deapi.ai/api/v2/keys/{id}"
payload := strings.NewReader("{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Accept", "<accept>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.deapi.ai/api/v2/keys/{id}")
.header("Accept", "<accept>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.deapi.ai/api/v2/keys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Accept"] = '<accept>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 42,
"name": "Production backend",
"preview": "42|...f3a",
"role": "api",
"status": "active",
"created_at": "2026-09-22T10:00:00+00:00",
"expires_at": null,
"last_used_at": "2026-09-22T11:30:00+00:00",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"ip_whitelist_count": 2,
"limit": 100,
"reset_interval": "monthly",
"limit_used": 41.25,
"limit_remaining": 58.75,
"limit_resets_at": "2026-10-22T10:00:00+00:00"
}
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "This API key does not have permission to access this endpoint.",
"code": "insufficient_permissions"
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "You have reached the limit of 100 active API keys — delete or deactivate the ones you no longer use.",
"code": "active_key_limit_reached"
}{
"message": "Too Many Attempts."
}Update Key
Switches an API-role key on or off, changes its expiry date, spend limit and reset window, and sets the addresses it may be used from. Needs an ADMIN key. The role cannot be changed; ADMIN keys are changed in the Dashboard only. Making a key active again counts toward the limit of active keys.
curl --request PATCH \
--url https://api.deapi.ai/api/v2/keys/{id} \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"active": false,
"expires_at": "2027-01-31T23:59:59Z",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"limit": 100,
"reset_interval": "daily"
}
'import requests
url = "https://api.deapi.ai/api/v2/keys/{id}"
payload = {
"active": False,
"expires_at": "2027-01-31T23:59:59Z",
"ip_whitelist": ["203.0.113.7", "198.51.100.0/24"],
"limit": 100,
"reset_interval": "daily"
}
headers = {
"Accept": "<accept>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
Accept: '<accept>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
active: false,
expires_at: '2027-01-31T23:59:59Z',
ip_whitelist: ['203.0.113.7', '198.51.100.0/24'],
limit: 100,
reset_interval: 'daily'
})
};
fetch('https://api.deapi.ai/api/v2/keys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.deapi.ai/api/v2/keys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'active' => false,
'expires_at' => '2027-01-31T23:59:59Z',
'ip_whitelist' => [
'203.0.113.7',
'198.51.100.0/24'
],
'limit' => 100,
'reset_interval' => 'daily'
]),
CURLOPT_HTTPHEADER => [
"Accept: <accept>",
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.deapi.ai/api/v2/keys/{id}"
payload := strings.NewReader("{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Accept", "<accept>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.deapi.ai/api/v2/keys/{id}")
.header("Accept", "<accept>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.deapi.ai/api/v2/keys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Accept"] = '<accept>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"active\": false,\n \"expires_at\": \"2027-01-31T23:59:59Z\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"daily\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 42,
"name": "Production backend",
"preview": "42|...f3a",
"role": "api",
"status": "active",
"created_at": "2026-09-22T10:00:00+00:00",
"expires_at": null,
"last_used_at": "2026-09-22T11:30:00+00:00",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"ip_whitelist_count": 2,
"limit": 100,
"reset_interval": "monthly",
"limit_used": 41.25,
"limit_remaining": 58.75,
"limit_resets_at": "2026-10-22T10:00:00+00:00"
}
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "This API key does not have permission to access this endpoint.",
"code": "insufficient_permissions"
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "You have reached the limit of 100 active API keys — delete or deactivate the ones you no longer use.",
"code": "active_key_limit_reached"
}{
"message": "Too Many Attempts."
}403 with code: insufficient_permissions — see API Keys.Authorizations
Sanctum personal access token, sent as Authorization: Bearer <token>. The token is opaque — it carries no claims and no embedded expiry, so do not attempt to decode it. Issue and revoke tokens from your account dashboard.
Headers
application/json Path Parameters
Body
false disables the key, true enables it again.
false
null removes the expiry date. A date must be in the future and no later than 2038-01-19 03:14:07 UTC, the latest instant this platform can store — a 422, not a silently shortened key.
"2027-01-31T23:59:59Z"
Replaces the whole list — entries are not merged with the ones already there. [] clears it and the key works from any address again; omitting the field leaves the list untouched, and an explicit null is refused.
20["203.0.113.7", "198.51.100.0/24"]
The new spend limit per window, in USD. null removes the limit; omitting the field leaves both the limit and what has been spent against it untouched. Changing the amount never resets the counter: raising it from 50 to 100 on a key that has already spent 50 leaves 50 of room, and lowering it below what has been spent accepts nothing more until the window resets.
0 <= x <= 999999.999999100
The new window. Changing it restarts the counter. Can be sent on its own, but only for a key that already has a limit; alongside "limit": null it is refused.
none, daily, weekly, monthly "daily"
Response
The key after the change.
Show child attributes
Show child attributes
Was this page helpful?