v66

OpenAPI 3.1.0raw.githubusercontent.com2026-08-0174265626.3 KB
portal

Reroll portal key

Reroll an API key owned by the authenticated portal session's end user, issuing a new key while preserving its configuration.

This is the portal-scoped variant of keys.rerollKey. It authenticates only with a portal session cookie and may only reroll keys owned by the session's external identity; any other key returns 404.

post/v2/portal.rerollKey

Request body

keyIdstring required

The database identifier of the key to reroll.

This is the unique ID returned when creating or listing keys, NOT the actual API key token. You can find this ID in:

  • The response from keys.createKey
  • Key verification responses
  • The Unkey dashboard
  • API key listing endpoints
expirationinteger required

Duration in milliseconds until the ORIGINAL key is revoked, starting from now.

This parameter controls the overlap period for key rotation:

  • Set to 0 to revoke the original key immediately
  • Positive values keep the original key active for the specified duration
  • Allows graceful migration by giving users time to update their credentials

Common overlap periods:

  • Immediate revocation: 0
  • 1 hour grace period: 3600000
  • 24 hours grace period: 86400000
  • 7 days grace period: 604800000
  • 30 days grace period: 2592000000

Example request

{
  "keyId": "key_2cGKbMxRyIzhCxo1Idjz8q",
  "expiration": 86400000
}

Response

Key rerolled successfully. The new plaintext key is returned exactly once.

Example response

{
  "meta": {
    "requestId": "req_123"
  },
  "data": {
    "keyId": "key_2cGKbMxRyIzhCxo1Idjz8q",
    "key": "prod_2cGKbMxRjIzhCxo1IdjH3arELti7Sdyc8w6XYbvtcyuBowPT"
  }
}