Rotate the API key you're calling with (old key invalidated immediately)
Replace the key used to authenticate **this** request with a fresh one that inherits its name, scopes and policy. The old key is revoked immediately, so the call that rotates a key is the last call that key can make. Capture the new value from this response before issuing another request — it is shown once and stored hashed. Use this for routine rotation or after a suspected leak. To retire a *different* key, use `DELETE /keys/{key_id}`. Unmetered.
Authorization
BearerAuth Your API key, sent as Authorization: Bearer wm_.... Keys are wm_ followed by 40 hex characters. Create one with POST /register (free, no auth) or POST /keys.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/keys/rotate"{ "api_key": "string", "rotated_at": "2019-08-24T14:15:22Z"}Create a new scoped API key
Create an additional API key on the authenticated account, with its own name, scopes and compliance policy. Scopes narrow what a key may do — issue a key scoped to `extract` for an agent that should never be able to start a crawl. A key can only grant scopes the calling key already holds. The raw key is returned **once, in this response**, and is stored hashed; there is no way to read it back. Unmetered.
Revoke an API key (stops working immediately)
Revoke a key on the authenticated account. The key stops authenticating immediately — there is no grace period, so revoke only after the replacement is deployed. Revocation is permanent and cannot be undone; mint a new key instead. The row remains listable with `revoked_at` set, so the audit trail survives. Unmetered.