Update API Key
Updates an API key’s name, permissions, expiration, or IP allowlist. Fields that are omitted keep their current value; default keys cannot be modified.
Authorizations
A company API key, company scoped JWT, app API key, or user OAuth token. You must prepend your key/token with the word 'Bearer', which will look like Bearer ***************************
Headers
Pins the request to a dated API version.
"2026-07-20"
Path Parameters
API key ID, prefixed apik_.
Body
When the API key should stop working, as an ISO 8601 timestamp. Omit (or pass null on update) for a key that never expires.
IPv4/IPv6 CIDR ranges allowed to use this key, for example ["203.0.113.0/24"]. Empty or null allows any IP.
A new human-readable name for the API key.
The permissions policy for the API key: explicit permission statements, or a system role to inherit from. Statements without a resources array default to the owning company (company keys) or every key-addressable resource (app keys).
Response
api key updated
When the API key was created, as an ISO 8601 timestamp.
When the API key stops working, as an ISO 8601 timestamp. null means it never expires.
API key ID, prefixed apik_.
IPv4/IPv6 CIDR ranges allowed to use this key. null or empty means requests are accepted from any IP.
Whether this is the resource's default API key. Default keys cannot be updated or deleted, only rotated.
Human-readable name identifying the API key, or null when none was set.
Masked version of the secret key, so the key can be recognized without revealing the full secret.
System role the key inherits its permissions from, or null when it uses an explicit permissions policy. Only account API keys can use a system role.
owner, admin, moderator, sales_manager, advertiser, null "owner"
When the API key was last updated, as an ISO 8601 timestamp.
The full secret used to authenticate requests. Returned only once, on create and rotate responses — store it immediately.

