nautir.ai
Management

Rotate a runtime key in place

POST
/api/v1/keys/{key_id}/rotate

Replaces the key's plaintext: same id, same policy binding, a new secret returned exactly once. The previous plaintext keeps authorizing for the grace window so callers can move over without an outage.

Authorization

managementKey
AuthorizationBearer <token>

An issued management key (sk-dz-…). One credential type across inference and management: scopes are properties of the issued key, set at issue time — keys:read, keys:write, usage:read, models:read. A key issued with no scopes holds all four. Each operation declares its required scope as x-required-scope.

In: header

Path Parameters

key_id*string

A runtime key id.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

curl -X POST "https://example.com/api/v1/keys/string/rotate" \  -H "Content-Type: application/json" \  -d '{}'
{  "id": "string",  "name": "string",  "kind": "string",  "disabled": true,  "expires_at": "2019-08-24T14:15:22Z",  "last_used_at": "2019-08-24T14:15:22Z",  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z",  "policy_id": "string",  "key_hint": "string",  "key": "string"}