# Create workspace api-keys keyId rotate

Issue a fresh secret for an existing key, keeping its name, target and scopes, and answer the new secret once. The previous secret stopped working the moment this returned, so whatever holds it must be updated before its next call. Admin and Enterprise only.

Access class: `workspace:admin`.

## Endpoint

`POST /v1/workspace/api-keys/{keyId}/rotate`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| keyId | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {},
  "params": {
    ":keyId": ""
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "key": {
      "boardId": "",
      "createdAt": "string",
      "definitionKey": "string",
      "id": "",
      "keyPrefix": "string",
      "lastUsedAt": "string",
      "memberEmail": "string",
      "name": "string",
      "rotatedAt": "string",
      "scopes": [
        "string"
      ],
      "targetLabel": "string"
    },
    "note": "string",
    "secret": "string"
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
