---
title: "Edit an application key"
method: PATCH
path: "/api/v2/application_keys/{app_key_id}"
tags: ["Key Management"]
---

# Edit an application key

`PATCH /api/v2/application_keys/{app_key_id}`

Edit an application key

## Path parameters

- `app_key_id` string, required

## Request body

- ApplicationKeyUpdateRequest — Request used to update an application key.
  - `data` ApplicationKeyUpdateData, required — Object used to update an application key.
    - `attributes` ApplicationKeyUpdateAttributes, required — Attributes used to update an application Key.
      - `name` string — Name of the application key.
      - `scopes` string[], nullable — Array of scopes to grant the application key.
    - `id` string, required — ID of the application key.
    - `type` 'application_keys', required — Application Keys resource type.

## Response `200`

OK

- ApplicationKeyResponse — Response for retrieving an application key.
  - `data` FullApplicationKey — Datadog application key.
    - `attributes` FullApplicationKeyAttributes — Attributes of a full application key.
      - `created_at` string, date-time — Creation date of the application key.
      - `key` string — The application key.
      - `last4` string — The last four characters of the application key.
      - `last_used_at` string, date-time, nullable — Last usage timestamp of the application key.
      - `name` string — Name of the application key.
      - `scopes` string[], nullable — Array of scopes to grant the application key.
    - `id` string — ID of the application key.
    - `relationships` ApplicationKeyRelationships — Resources related to the application key.
      - `owned_by` RelationshipToUser — Relationship to user.
        - `data` RelationshipToUserData, required — Relationship to user object.
          - `id` string, required — A unique identifier that represents the user.
          - `type` 'users', required — Users resource type.
    - `type` 'application_keys' — Application Keys resource type.
  - `included` ApplicationKeyResponseIncludedItem[] — Array of objects related to the application key.
    - union — An object related to an application key.
      - User — User object returned by the API.
        - `attributes` UserAttributes — Attributes of user object returned by the API.
          - `created_at` string, date-time — The ISO 8601 timestamp of when the user account was created.
          - `disabled` boolean — Whether the user account is deactivated. Disabled users cannot log in.
          - `email` string — The email address of the user, used for login and notifications.
          - `handle` string — The unique handle (username) of the user, typically matching their email prefix.
          - `icon` string — URL of the user's profile icon, typically a Gravatar URL derived from the email address.
          - `last_login_time` string, date-time, nullable — The ISO 8601 timestamp of the user's most recent login, or null if the user has never logged in.
          - `mfa_enabled` boolean — Whether multi-factor authentication (MFA) is enabled for the user's account.
          - `modified_at` string, date-time — The ISO 8601 timestamp of when the user account was last modified.
          - `name` string, nullable — The full display name of the user as shown in the Datadog UI.
          - `service_account` boolean — Whether this is a service account rather than a human user. Service accounts are used for programmatic API access.
          - `status` string — The current status of the user account (for example, `Active`, `Pending`, or `Disabled`).
          - `title` string, nullable — The job title of the user (for example, "Senior Engineer" or "Product Manager").
          - `uuid` string — The globally unique identifier (UUID) of the user.
          - `verified` boolean — Whether the user's email address has been verified.
        - `id` string — ID of the user.
        - `relationships` UserResponseRelationships — Relationships of the user object returned by the API.
          - `org` RelationshipToOrganization — Relationship to an organization.
            - `data` RelationshipToOrganizationData, required — Relationship to organization object.
              - …
          - `other_orgs` RelationshipToOrganizations — Relationship to organizations.
            - `data` RelationshipToOrganizationData[], required — Relationships to organization objects.
              - …
          - `other_users` RelationshipToUsers — Relationship to users.
            - `data` RelationshipToUserData[], required — Relationships to user objects.
              - …
          - `roles` RelationshipToRoles — Relationship to roles.
            - `data` RelationshipToRoleData[] — An array containing type and the unique identifier of a role.
              - …
        - `type` 'users' — Users resource type.
      - Role — Role object returned by the API.
        - `attributes` RoleAttributes — Attributes of the role.
          - `created_at` string, date-time — Creation time of the role.
          - `modified_at` string, date-time — Time of last role modification.
          - `name` string — The name of the role. The name is neither unique nor a stable identifier of the role.
          - `receives_permissions_from` string[] — The managed role from which this role automatically inherits new permissions. Specify one of the following: "Datadog Admin Role", "Datadog Standard Role", or "Datadog Read Only Role". If empty or not specified, the role does not automatically inherit permissions from any managed role.
          - `user_count` integer — Number of users with that role.
        - `id` string — The unique identifier of the role.
        - `relationships` RoleResponseRelationships — Relationships of the role object returned by the API.
          - `permissions` RelationshipToPermissions — Relationship to multiple permissions objects.
            - `data` RelationshipToPermissionData[] — Relationships to permission objects.
              - …
        - `type` 'roles', required — Roles type.
      - LeakedKey — The definition of LeakedKey object.
        - `attributes` LeakedKeyAttributes, required — The definition of LeakedKeyAttributes object.
          - `date` string, date-time, required — The LeakedKeyAttributes date.
          - `leak_source` string — The LeakedKeyAttributes leak_source.
        - `id` string, required — The LeakedKey id.
        - `type` 'leaked_keys', required — The definition of LeakedKeyType object.

## Other responses

- `400` — Bad Request
- `403` — Forbidden
- `404` — Not Found
- `429` — Too many requests

---

[API](https://skmtc.net/datadog/apis/api-v2.md) · [All operations](https://skmtc.net/datadog/apis/api-v2/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/datadog/api-v2/revisions/da68bf029e4c/schema)
