A valid request URL is required to generate request examples{
"id": "6e2d3c4b-5f6a-7b8c-9d0e-1f2a3b4c5d6e",
"name": "Production",
"prefix": "uk_ck_live_89abcdef",
"created_at": "2026-07-30T12:05:00Z",
"key": "uk_ck_live_89abcdef0123456789abcdef0123456789abcdef01234567"
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Roll one of my team's API keys
Replaces a key: the old one dies and a new one is born under the same name, in one transaction — there is no moment when the name exists twice or not at all. The answer carries the new plaintext, shown once like a creation’s. Owner-only.
Rolling is the recovery for a leaked or lost key: nothing can read a stored key back, so the replacement is a new secret, and every caller holding the old string is cut off at once.
A valid request URL is required to generate request examples{
"id": "6e2d3c4b-5f6a-7b8c-9d0e-1f2a3b4c5d6e",
"name": "Production",
"prefix": "uk_ck_live_89abcdef",
"created_at": "2026-07-30T12:05:00Z",
"key": "uk_ck_live_89abcdef0123456789abcdef0123456789abcdef01234567"
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Authorizations
A contact session token, uk_ct_…. Belongs to one of the developer's own users, and reads only that user's data.
Headers
The customer this call is acting inside — the same arrangement as X-Organization-Id, one plane down. Switching customers is navigation, not a mutation: nothing is stored, you send a different header, and the membership JOIN behind it decides what you may do there. An id you are not a member of matches no row and answers 404. Absent, the contact's oldest membership answers.
Path Parameters
The key being replaced.
Response
The replacement, with its plaintext — shown once, here. The rolled key is already dead.