---
title: "POST /rotate-key"
method: POST
path: "/rotate-key"
tags: ["v2"]
---

# POST /rotate-key

`POST /rotate-key`

## Request body

- RotateKey — of it.
  - `json` boolean — Set output format to JSON
  - `name` string, required — Key name
  - `new-cert-pem-data` string — The new pem encoded certificate for the classic key. relevant only for keys provided by user ('bring-your-own-key')
  - `new-key-data` string — The new base64 encoded value for the classic key. relevant only for keys provided by user ('bring-your-own-key')
  - `token` string — Authentication token (see `/auth` and `/configure`)
  - `uid-token` string — The universal identity token, Required only for universal_identity authentication

## Response `200`

rotateKeyResponse wraps response body.

- RotateKeyOutput — RotateKeyOutput defines output of RotateKey operation
  - `classic_key_gw_url` string
  - `item_type` string
  - `new_item_version` integer
  - `next_rotation_date` string, date-time

## Other responses

- `default` — errorResponse wraps any error to return it as a JSON object with one "error" field.

---

[API](https://skmtc.net/akeyless/apis/akeyless-api.md) · [All operations](https://skmtc.net/akeyless/apis/akeyless-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/akeyless/akeyless-api/versions/0ceb25634501/schema)
