Rotate an API key
curl --request POST \
--url https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"grace_seconds": 123
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({grace_seconds: 123})
};
fetch('https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate"
payload = { "grace_seconds": 123 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "c342e2b8-e4ca-4421-8740-3ed85089629b",
"key": "ig_live_...",
"key_prefix": "ig_live_efgh",
"replacement_for_key_id": "33c19c9d-b9e1-4928-8369-1995c2726c9b",
"rotation_grace_expires_at": "2026-08-18T20:00:00Z"
}
Credentials
Rotate an API key
Create a replacement key with a bounded rollout grace period.
POST
/
v1
/
workspaces
/
{workspace_id}
/
api-keys
/
{key_id}
/
rotate
Rotate an API key
curl --request POST \
--url https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"grace_seconds": 123
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({grace_seconds: 123})
};
fetch('https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://agent.infragrid.ai/v1/workspaces/{workspace_id}/api-keys/{key_id}/rotate"
payload = { "grace_seconds": 123 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "c342e2b8-e4ca-4421-8740-3ed85089629b",
"key": "ig_live_...",
"key_prefix": "ig_live_efgh",
"replacement_for_key_id": "33c19c9d-b9e1-4928-8369-1995c2726c9b",
"rotation_grace_expires_at": "2026-08-18T20:00:00Z"
}
Requires an authenticated dashboard session. Returns
201 Created.
uuid
required
Workspace that owns the current key.
uuid
required
Key metadata identifier to replace.
integer
default:"86400"
required
Time the old key may remain valid while consumers roll over. Minimum 0; maximum 604,800 seconds (seven days).
Response
{
"id": "c342e2b8-e4ca-4421-8740-3ed85089629b",
"key": "ig_live_...",
"key_prefix": "ig_live_efgh",
"replacement_for_key_id": "33c19c9d-b9e1-4928-8369-1995c2726c9b",
"rotation_grace_expires_at": "2026-08-18T20:00:00Z"
}
string
required
Replacement plaintext
ig_live_ secret. Returned only once.uuid | null
required
ID of the key this credential replaces.
string | null
required
Timestamp after which the old key is no longer valid.
1
Store the replacement
Write the one-time secret to your server-side secret manager.
2
Deploy consumers
Update every service before the grace window closes.
3
Verify and revoke
Confirm the new prefix is in use, then revoke the old key early when safe.
Last modified on August 17, 2026