---
title: "Rotate agent key"
method: POST
path: "/agent-keys/{keyId}/rotate"
tags: ["Agent Keys"]
---

# Rotate agent key

`POST /agent-keys/{keyId}/rotate`

Rotate an agent key. The new secret is returned only once.

## Path parameters

- `keyId` string, required — Agent key ID (agk_*).

## Headers

- `Idempotency-Key` string, required
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `expiresInSeconds` integer, required — Grace period in seconds for the previous key (0 = immediate cutover, max 86400).
      - `tags` object — Tags applied to the replacement agent key.

## Response `200`

Successful Response

- object
  - `data` object, required
    - `type` 'agentKey', required — Resource type. Always `agentKey`.
    - `id` string, required — Agent key ID (agk_*).
    - `attributes` object, required
      - `agentKeyPrefix` string, required — Non-secret prefix of the agent key, e.g. `ak_ntl_prod_abc123`.
      - `status` 'ACTIVE' | 'REVOKED', required — Agent key status.
      - `createdAt` string, date-time, required — RFC 3339 timestamp when this key was created.
      - `lastUsedAt` string, date-time, nullable, required — RFC 3339 timestamp when this key was last used, or null when never used.
      - `revokedAt` string, date-time, nullable, required — RFC 3339 timestamp when this key was revoked, or null while active.
      - `createdBy` string, nullable, required — User who created this key (usr_*).
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*).
      - `expiresAt` string, date-time, nullable, required — RFC 3339 timestamp when this key stops authenticating, or null when it has no scheduled expiration.
      - `tags` object, required — Metadata visible to anyone who can read the resource.
      - `agentKey` string, required — Full agent key secret. Returned only once.
      - `previousKeyExpiresAt` string, date-time, nullable, required — RFC 3339 timestamp when the previous key stops authenticating, or null for immediate cutover.
    - `relationships` object, required
      - `party` object, required — Party that owns the agent key.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required — Resource type. Always `party`.
          - `id` string, required
      - `agent` object, required — Agent this key is bound to.
        - `data` object, required — Related resource identifier.
          - `type` 'agent', required — Resource type. Always `agent`.
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error. The response contains one error object for each invalid request value.
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-09-02** `c7c12da5915f` — 12 info
  - added the optional property `errors/items/meta/limitScope` to the response with the `400` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `401` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `403` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `404` status
  - …8 more
- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 info
  - `header` request parameter `X-Agent-ID` was deprecated
- **2026-08-14** `7271de071ca5` — 2 info
  - added the new optional request property `data/attributes/tags`
  - added the required property `data/attributes/tags` to the response with the `200` status
- **2026-07-26** `270e233e401c` — 1 warning
  - for the `header` request parameter `Idempotency-Key`, the maxLength was set to `255`

[Change history](https://skmtc.dev/natural/apis/natural-api/changes/agent-keys/:keyId/rotate/post.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc.dev/natural/apis/natural-api/revisions/b61b8441fba4?raw)
