api_keys.rotate
Replace your API key while preserving scope ceilings and revoking the original.
/api/v1/accounting/api_keys.rotatePermissions
Who can call it
Retries
MCP
accounting_api_keys_rotateCan't be undone
Fields
idstring (ID)RequiredThe record's ID.
expectedRevisionintegerRequiredThe record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.
at most 9007199254740991 · greater than 0
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–160 characters
namestringA display name.
1–100 characters · Matches ^[^\u0000-\u001f\u007f]+$
scopesarray of enum valuesWhat the API key may do. A key can never do more than the person who made it.
accounting:readaccounting:writeaccounting:adminmail:readmail:writemail:securityapi_keys:managemailboxes:search1–8 items
expiresAtstring (date-time)When this stops working, as an ISO 8601 date and time.
Example
curl https://app.getoatmilk.com/api/v1/accounting/api_keys.rotate \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
"expectedRevision": 3
}'{
"data": { … }
}Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/api_keys.rotate \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
"expectedRevision": 3
}'More in Administration.