Skip to main content
Use this endpoint to rotate an agent’s API key. It atomically revokes all currently active keys for the specified agent and issues a single fresh key with a new 30-day expiry. Rotate keys on a regular schedule or immediately if you suspect a key has been compromised. After rotation, update any service or environment that was using the old key — existing sessions started with a revoked key will continue to function until their session JWTs expire, but no new sessions can be created with the old key.
Only users with Admin privilege (privilege=1) on the project can create or rotate keys.

Endpoint

Base URL: http://localhost:8000

Request headers

string
required
JWT obtained from the OTAS login endpoint, identifying the calling user.
string
required
UUID of the project the agent belongs to.

Request body

string
required
UUID of the agent for which to rotate the key.

Response

number
1 on success.
string
"agent_key_created" on success.
object
The full api_key value is returned only in this response. All previously active keys for the agent are revoked before the new one is issued. Save the new key to a secrets manager or environment variable immediately — it cannot be retrieved again.

Revoking a specific key without rotation

If you need to revoke a single key without issuing a replacement, use:
Request body:
This requires the same X-OTAS-USER-TOKEN and X-OTAS-PROJECT-ID headers and Admin privilege. It sets the key as inactive immediately without creating a new key.

Errors

Example

cURL
Response (201)