v1
latestOpenAPI 3.1.02026-07-26497885.9 KBRotate API key
Rotate an existing App API Key (Rich Authentication Token) for a OneSignal app. Useful when a token is compromised or needs replacement without creating a new key from scratch.
post/apps/{app_id}/auth/tokens/{token_id}/rotate
Path parameters
app_idstring required
Your OneSignal App ID in UUID v4 format. See Keys & IDs.
token_idstring required
The OneSignal-generated ID specific to the API key. This is not the API key itself. It is returned when creating an API key with Create API key. It can be found in the OneSignal dashboard and in the response body of the View API keys request.
Headers
Content-Typestring required
Authorizationstring required
Your Organization API key with prefix Key . See Keys & IDs.
Response
The rotated key's new secret. Only formatted_token is populated; everything else stays the same as before the rotate. Update your integration with the new secret immediately.