key management

Update Key Fn

Update an existing API key's parameters.

Parameters:

  • key: Optional[str] - The key to update. Either key or key_alias must be provided.
  • key_alias: Optional[str] - User-friendly key alias. If key is omitted, also identifies the key to update (must match exactly one key, same as /key/delete's key_aliases)
  • user_id: Optional[str] - User ID associated with key
  • team_id: Optional[str] - Team ID associated with key
  • agent_id: Optional[str] - The agent id associated with the key.
  • organization_id: Optional[str] - The organization id of the key.
  • budget_id: Optional[str] - The budget id associated with the key. Created by calling /budget/new.
  • models: Optional[list] - Model_name's a user is allowed to call
  • tags: Optional[List[str]] - Tags for organizing keys (Enterprise only)
  • prompts: Optional[List[str]] - List of prompts that the key is allowed to use.
  • enforced_params: Optional[List[str]] - List of enforced params for the key (Enterprise only). Docs
  • spend: Optional[float] - Amount spent by key
  • max_budget: Optional[float] - Max budget for key
  • model_max_budget: Optional[Dict[str, BudgetConfig]] - Model-specific budgets {"gpt-4": {"budget_limit": 0.0005, "time_period": "30d"}}
  • budget_fallbacks: Optional[Dict[str, List[str]]] - Per-model fallback chain tried in order when that model's own model_max_budget is exceeded, e.g. {"gpt-4o": ["gpt-4o-mini"]}.
  • budget_duration: Optional[str] - Budget reset period ("30d", "1h", etc.)
  • soft_budget: Optional[float] - [TODO] Soft budget limit (warning vs. hard stop). Will trigger a slack alert when this soft budget is reached.
  • max_parallel_requests: Optional[int] - Rate limit for parallel requests
  • metadata: Optional[dict] - Metadata for key. Example {"team": "core-infra", "app": "app2"}
  • tpm_limit: Optional[int] - Tokens per minute limit
  • rpm_limit: Optional[int] - Requests per minute limit
  • model_rpm_limit: Optional[dict] - Model-specific RPM limits {"gpt-4": 100, "claude-v1": 200}
  • mcp_rpm_limit: Optional[dict] - Per-MCP-server RPM limits, keyed by MCP server name {"github": 100, "slack": 200}
  • tag_rpm_limit: Optional[dict] - Per-request-tag RPM limits, keyed by request tag {"cell-1": 1000, "cell-2": 500}. Each tag gets an independent counter; absent tags fall back to the key-level rpm limit.
  • model_tpm_limit: Optional[dict] - Model-specific TPM limits {"gpt-4": 100000, "claude-v1": 200000}
  • default_estimated_output_tokens: Optional[int] - Proxy admin only. Expected output tokens reserved for TPM limiting when a request omits max_tokens. Positive integer.
  • default_estimated_output_tokens_per_model: Optional[dict] - Proxy admin only. Per-model override of the above {"gpt-4": 4096, "gpt-3.5-turbo": 1024}
  • tpm_limit_type: Optional[str] - TPM rate limit type - "best_effort_throughput", "guaranteed_throughput", or "dynamic"
  • rpm_limit_type: Optional[str] - RPM rate limit type - "best_effort_throughput", "guaranteed_throughput", or "dynamic"
  • allowed_cache_controls: Optional[list] - List of allowed cache control values
  • duration: Optional[str] - Key validity duration ("30d", "1h", etc.), null to never expire, or "-1" to never expire (deprecated, use null)
  • permissions: Optional[dict] - Key-specific permissions
  • send_invite_email: Optional[bool] - Send invite email to user_id
  • guardrails: Optional[List[str]] - List of active guardrails for the key
  • policies: Optional[List[str]] - List of policy names to apply to the key. Policies define guardrails, conditions, and inheritance rules.
  • disable_global_guardrails: Optional[bool] - Whether to disable global guardrails for the key.
  • throttle_on_budget_exceeded: Optional[bool] - When the key exceeds its max_budget, throttle its tpm/rpm to the global budget_exceeded_throttle_percentage instead of blocking the key entirely.
  • enable_prompt_caching: Optional[bool] - Auto-inject prompt caching breakpoints (Anthropic cache_control markers) on requests made with this key. Anthropic and Bedrock Claude models only.
  • prompts: Optional[List[str]] - List of prompts that the key is allowed to use.
  • blocked: Optional[bool] - Whether the key is blocked
  • aliases: Optional[dict] - Model aliases for the key - Docs
  • config: Optional[dict] - [DEPRECATED PARAM] Key-specific config.
  • temp_budget_increase: Optional[float] - Temporary budget increase for the key (Enterprise only).
  • temp_budget_expiry: Optional[str] - Expiry time for the temporary budget increase (Enterprise only).
  • allowed_routes: Optional[list] - List of allowed routes for the key. Store the actual route or store a wildcard pattern for a set of routes. Example - ["/chat/completions", "/embeddings", "/keys/*"]
  • allowed_passthrough_routes: Optional[list] - List of allowed pass through routes for the key. Store the actual route or store a wildcard pattern for a set of routes. Example - ["/my-custom-endpoint"]. Use this instead of allowed_routes, if you just want to specify which pass through routes the key can access, without specifying the routes. If allowed_routes is specified, allowed_passthrough_routes is ignored.
  • prompts: Optional[List[str]] - List of allowed prompts for the key. If specified, the key will only be able to use these specific prompts.
  • object_permission: Optional[LiteLLM_ObjectPermissionBase] - key-specific object permission. Example - {"vector_stores": ["vector_store_1", "vector_store_2"], "agents": ["agent_1", "agent_2"], "agent_access_groups": ["dev_group"]}. IF null or {} then no object permission.
  • auto_rotate: Optional[bool] - Whether this key should be automatically rotated
  • rotation_interval: Optional[str] - How often to rotate this key (e.g., '30d', '90d'). Required if auto_rotate=True
  • allowed_vector_store_indexes: Optional[List[dict]] - List of allowed vector store indexes for the key. Example - [{"index_name": "my-index", "index_permissions": ["write", "read"]}]. If specified, the key will only be able to use these specific vector store indexes. Create index, using /v1/indexes endpoint.
  • router_settings: Optional[UpdateRouterConfig] - key-specific router settings. Example - {"model_group_retry_policy": {"gpt-4": {"RateLimitErrorRetries": 5}}}. IF null or {} then no router settings.
  • access_group_ids: Optional[List[str]] - List of access group IDs to associate with the key. Access groups define which models a key can access. Example - ["access_group_1", "access_group_2"].
  • budget_limits: Optional[list] - List of concurrent budget windows for the key. Each window specifies a budget_limit, time_period, and optional budget_duration. Example - [{"budget_limit": 10.0, "time_period": "1d"}, {"budget_limit": 50.0, "time_period": "7d"}].

Example:

curl --location 'http://0.0.0.0:4000/key/update'     --header 'Authorization: Bearer sk-1234'     --header 'Content-Type: application/json'     --data '{
    "key": "sk-1234",
    "key_alias": "my-key",
    "user_id": "user-1234",
    "team_id": "team-1234",
    "max_budget": 100,
    "metadata": {"any_key": "any-val"},
}'
post/key/update

Headers

litellm-changed-bystring nullable

The litellm-changed-by header enables tracking of actions performed by authorized users on behalf of other users, providing an audit trail for accountability

The litellm-changed-by header enables tracking of actions performed by authorized users on behalf of other users, providing an audit trail for accountability

Request body

key_aliasstring nullable
durationstring nullable
spendnumber nullable
max_budgetnumber nullable
user_idstring nullable
team_idstring nullable
agent_idstring nullable
max_parallel_requestsinteger nullable
metadataobject nullable
tpm_limitinteger nullable
rpm_limitinteger nullable
budget_durationstring nullable
configobject nullable
permissionsobject nullable
model_max_budgetobject nullable
budget_fallbacksobject nullable
model_rpm_limitobject nullable
model_tpm_limitobject nullable
mcp_rpm_limitobject nullable
tag_rpm_limitobject nullable
guardrailsstring[] nullable
policiesstring[] nullable
promptsstring[] nullable
blockedboolean nullable
aliasesobject nullable
keystring nullable
default_estimated_output_tokensinteger nullable
default_estimated_output_tokens_per_modelobject nullable
budget_idstring nullable
tagsstring[] nullable
disable_global_guardrailsboolean nullable
enable_prompt_cachingboolean nullable
throttle_on_budget_exceededboolean nullable
enforced_paramsstring[] nullable
rpm_limit_type'guaranteed_throughput' | 'best_effort_throughput' | 'dynamic' nullable
tpm_limit_type'guaranteed_throughput' | 'best_effort_throughput' | 'dynamic' nullable
access_group_idsstring[] nullable
temp_budget_increasenumber nullable
temp_budget_expirystring date-time nullable
auto_rotateboolean nullable
rotation_intervalstring nullable
organization_idstring nullable

Response

Successful Response

{"stackTrail":"paths:/key/update:post:responses:200:content:application/json:schema","oasType":"schema","type":"unknown"}

Changes

Changed in 1 of the 42 revisions of this API.17

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property //

      new-optional-request-property

    • ○

      added the new optional request property //

      new-optional-request-property

    • ○

      added the new optional request property //

      new-optional-request-property

    • ○

      added the new optional request property //

      new-optional-request-property

    • ○

      added the new optional request property //

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      added the new optional request property

      new-optional-request-property

    • ○

      the request property became optional

      request-property-became-optional

    • ○

      request property list-of-types was widened by adding types null to media type application/json

      request-property-list-of-types-widened

    • ○

      added the optional property // to the response with the status

      response-optional-property-added

    • ○

      added the optional property // to the response with the status

      response-optional-property-added

    This revision also has 5 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog