> ## Documentation Index
> Fetch the complete documentation index at: https://docs.redbark.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate an API key

> Mints a replacement with the same name, scopes, allowlist and expiry and returns its secret once. The old key keeps working until the grace period ends (max 7 days). Optional JSON body `{ "grace": "7d" }`.



## OpenAPI

````yaml /openapi/v2.json post /api_keys/{id}/rotate
openapi: 3.1.0
info:
  title: Redbark API
  version: 2026-10-01.wattle
  description: >-
    Everything a user can do in the dashboard, by API key. Send
    `Redbark-Version` on every request; see the conventions guide for ids,
    lists, errors and idempotency.
servers:
  - url: https://api.redbark.com/v2
security:
  - Bearer: []
    RedbarkVersion: []
tags:
  - name: Account
    description: The authenticated account, its plan and the key in use.
  - name: API keys
    description: Create, scope, rotate and revoke API keys.
  - name: Connections
    description: Linked banks and brokerages, and their lifecycle.
  - name: Consents
    description: Open Banking consents behind each connection.
  - name: Accounts
    description: Bank and brokerage accounts, live balances and details.
  - name: Transactions
    description: Transactions read live from the provider.
  - name: Holdings
    description: Brokerage positions.
  - name: Trades
    description: Brokerage trade history.
  - name: Categories
    description: The category taxonomy and provider categories.
  - name: Syncs
    description: Syncs from accounts to destinations.
  - name: Sync runs
    description: Individual sync executions.
  - name: Rules
    description: Rulesets and rules that transform transactions during a sync.
  - name: Destinations
    description: 'Where synced data lands: Sheets, Airtable, Notion, YNAB, webhooks.'
  - name: Link sessions
    description: Hosted flows that connect a bank or brokerage.
  - name: Destination links
    description: Hosted flows that authorise a destination.
  - name: Institutions
    description: Banks available to link.
  - name: Event destinations
    description: Endpoints that receive signed events.
  - name: Events
    description: What happened, and redelivery.
paths:
  /api_keys/{id}/rotate:
    post:
      tags:
        - API keys
      summary: Rotate an API key
      description: >-
        Mints a replacement with the same name, scopes, allowlist and expiry and
        returns its secret once. The old key keeps working until the grace
        period ends (max 7 days). Optional JSON body `{ "grace": "7d" }`.
      operationId: rotate_api_key
      parameters:
        - schema:
            type: string
            description: The id of the object.
            example: key_3K1nTq8cZ5yWvR2mPd7Lx9
          required: true
          description: The id of the object.
          name: id
          in: path
      responses:
        '201':
          description: The replacement key, with its secret
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKey'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Key lacks a scope, plan lacks the feature, or IP not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No such resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: State conflict or Idempotency-Key conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limited; see Retry-After
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error; quote request_id to support
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ApiKey:
      type: object
      properties:
        id:
          type: string
          example: key_3K1nTq8cZ5yWvR2mPd7Lx9
        object:
          type: string
          enum:
            - api_key
        name:
          type: string
        prefix:
          type: string
          description: First 16 characters of the secret, for display
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/Scope'
        legacy:
          type: boolean
          description: Created before scopes existed; holds every :read scope
        secret:
          type:
            - string
            - 'null'
          description: Only present on create and rotate responses
        allowed_ips:
          type:
            - array
            - 'null'
          items:
            type: string
        expires_at:
          type:
            - string
            - 'null'
          format: date-time
          example: '2026-08-21T09:30:00.000Z'
        expiring_at:
          type:
            - string
            - 'null'
          format: date-time
          example: '2026-08-21T09:30:00.000Z'
          description: 'Set after rotate: when this key stops working'
        last_used_at:
          type:
            - string
            - 'null'
          format: date-time
          example: '2026-08-21T09:30:00.000Z'
        rotated_from:
          type:
            - string
            - 'null'
        status:
          type: string
          enum:
            - active
            - expiring
            - revoked
            - expired
        metadata:
          type:
            - object
            - 'null'
          additionalProperties:
            type: string
            maxLength: 500
          description: Up to 50 string pairs. Set a key to null in an update to unset it.
        livemode:
          type: boolean
        created:
          type: string
          format: date-time
          example: '2026-08-21T09:30:00.000Z'
        updated:
          type: string
          format: date-time
          example: '2026-08-21T09:30:00.000Z'
      required:
        - id
        - object
        - name
        - prefix
        - scopes
        - legacy
        - secret
        - allowed_ips
        - expires_at
        - expiring_at
        - last_used_at
        - rotated_from
        - status
        - metadata
        - livemode
        - created
        - updated
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - invalid_request_error
                - authentication_error
                - permission_error
                - rate_limit_error
                - idempotency_error
                - upstream_error
                - api_error
            code:
              type: string
            message:
              type: string
            param:
              type:
                - string
                - 'null'
            doc_url:
              type: string
            request_id:
              type: string
          required:
            - type
            - code
            - message
            - param
            - doc_url
            - request_id
      required:
        - error
    Scope:
      type: string
      enum:
        - account:read
        - connections:read
        - connections:write
        - data:read
        - categories:read
        - categories:write
        - destinations:read
        - destinations:write
        - syncs:read
        - syncs:write
        - rules:read
        - rules:write
        - events:read
        - events:write
        - keys:write
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: 'Authorization: Bearer rbk_live_...'
    RedbarkVersion:
      type: apiKey
      in: header
      name: Redbark-Version
      description: >-
        The API release your integration is built against, e.g.
        2026-10-01.wattle. Required on every request.

````