---
title: "Rotate Org Api Key"
method: POST
path: "/api/organization/api-keys/{key_id}/rotate"
tags: ["organization", "api-keys"]
---

# Rotate Org Api Key

`POST /api/organization/api-keys/{key_id}/rotate`

Mint a replacement with the same name, scopes and rate limit; the old
key keeps working until ``grace_until`` (default 24h) and then auto-revokes.

## Path parameters

- `key_id` string, required

## Request body

- RotateApiKeyRequest
  - `grace_hours` integer — How long the old key keeps working after rotation (0 to 168 hours).
  - `expires_in` '90d' | '1y' | '2y', nullable
  - `expires_at` string, date-time, nullable

## Response `200`

Successful Response

- RotateApiKeyResponse
  - `token` string, required
  - `key` ApiKeyPublic, required
    - `id` string, required
    - `org_id` string, required
    - `name` string, required
    - `key_prefix` string, nullable
    - `scopes` string[]
    - `created_by_user_id` string, nullable
    - `created_at` string, nullable
    - `expires_at` string, nullable
    - `revoked` boolean
    - `revoked_at` string, nullable
    - `last_used_at` string, nullable
    - `last_used_ip` string, nullable
    - `rate_limit_per_minute` integer, nullable
    - `rotated_from_key_id` string, nullable
    - `grace_until` string, nullable
  - `replaced_key_id` string, required
  - `grace_until` string, nullable

## Other responses

- `422` — Validation Error

## Changes

- **2026-09-18** `a15aa5b1bb56` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/every/apis/every-api/changes/api/organization/api-keys/:key_id/rotate/post.md)

---

[API](https://skmtc.dev/every/apis/every-api.md) · [All operations](https://skmtc.dev/every/apis/every-api/llms.txt) · [OpenAPI document](https://skmtc.dev/every/apis/every-api/revisions/e1ba6d9dba94?raw)
