> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate an API key

> Issue a fresh token and invalidate every previous one, in a single call. Also the only way to see a token after creation.

Rotation swaps the credential under the key: same ID, same name, same scopes, new token. Every token the key issued before this call stops working the moment it returns.

<CodeGroup>
  ```typescript TypeScript theme={null}
  const key = await client.apiKeys.rotate(apiKeyId, { workspaceId });

  // The new token, shown this once. The old one is already dead.
  console.log(key.spec.token);
  ```

  ```go Go theme={null}
  key, err := client.APIKeys.Rotate(ctx, apiKeyID,
  	cadenya.APIKeyRotateParams{WorkspaceID: cadenya.String(workspaceID)})
  if err != nil {
  	log.Fatal(err)
  }

  // The new token, shown this once. The old one is already dead.
  log.Println(key.Spec.Token)
  ```

  ```ruby Ruby theme={null}
  key = cadenya.api_keys.rotate(api_key_id, workspace_id: workspace_id)

  # The new token, shown this once. The old one is already dead.
  puts key.spec.token
  ```

  ```bash cURL theme={null}
  curl -X POST "https://api.cadenya.com/v1/workspaces/${WORKSPACE_ID}/api_keys/${API_KEY_ID}:rotate" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}" \
    -H "Content-Type: application/json" \
    -d '{}'
  ```
</CodeGroup>

<Warning>
  Invalidation is immediate and covers every previous token, not only the latest. Any service still holding the old value starts failing auth on its next request, so update every consumer of the key as part of the same deploy, not after it.
</Warning>

## Rotate is also the recovery path

Cadenya never shows a token after the response that minted it. Lost the value? There is nothing to look up, only this call: rotate, capture `spec.token`, and move on. That is the "lose it, rotate it" rule from the [API key model](/docs/guides/api-key-scopes).

## Related

<CardGroup cols={2}>
  <Card title="Create an API key" icon="key" href="/docs/api-reference/apikeyservice/create-a-new-api-key">
    The other response that carries a token.
  </Card>

  <Card title="Disable an API key" icon="ban" href="/docs/api-reference/apikeyservice/disable-an-api-key">
    When you want the key off, not reissued.
  </Card>

  <Card title="Rotate the global API key" icon="globe" href="/docs/api-reference/globalapikeyservice/rotate-the-global-api-key">
    The same motion for the account-wide key.
  </Card>

  <Card title="Update an API key" icon="pen" href="/docs/api-reference/apikeyservice/update-an-api-key">
    Change scopes without touching the token.
  </Card>
</CardGroup>


## OpenAPI

````yaml post /v1/workspaces/{workspaceId}/api_keys/{id}:rotate
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/workspaces/{workspaceId}/api_keys/{id}:rotate:
    post:
      tags:
        - APIKeyService
        - API Keys
      summary: Rotate an API key
      description: >-
        Rotates an API key and returns a new token. All previous tokens for this
        key are invalidated.
      operationId: APIKeyService_RotateAPIKey
      parameters:
        - name: workspaceId
          in: path
          description: The workspace the API key belongs to (path).
          required: true
          schema:
            type: string
            example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
        - name: id
          in: path
          description: >-
            The API key to rotate. A new token is issued and any existing token
            is
             invalidated.
          required: true
          schema:
            type: string
            example: apikey_01HXKD2E5NQM3T9AYWCFCSPNQY
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RotateAPIKeyRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: >-
            import Cadenya from '@cadenya/cadenya';


            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });


            const apiKey = await
            client.apiKeys.rotate('apikey_01HXKD2E5NQM3T9AYWCFCSPNQY', {
              workspaceId: 'workspace_01HXKD2E5NQM3T9AYWCF133E3Q',
            });


            console.log(apiKey.metadata);
        - lang: Python
          source: |-
            import os
            from cadenya import Cadenya

            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )
            api_key = client.api_keys.rotate(
                id="apikey_01HXKD2E5NQM3T9AYWCFCSPNQY",
                workspace_id="workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
            )
            print(api_key.metadata)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tapiKey, err := client.APIKeys.Rotate(\n\t\tcontext.TODO(),\n\t\t\"apikey_01HXKD2E5NQM3T9AYWCFCSPNQY\",\n\t\tcadenya.APIKeyRotateParams{\n\t\t\tWorkspaceID: cadenya.String(\"workspace_01HXKD2E5NQM3T9AYWCF133E3Q\"),\n\t\t},\n\t)\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", apiKey.Metadata)\n}\n"
        - lang: Ruby
          source: |-
            require "cadenya"

            cadenya = Cadenya::Client.new(api_key: "My API Key")

            api_key = cadenya.api_keys.rotate(
              "apikey_01HXKD2E5NQM3T9AYWCFCSPNQY",
              workspace_id: "workspace_01HXKD2E5NQM3T9AYWCF133E3Q"
            )

            puts(api_key)
        - lang: CLI
          source: |-
            cadenya api-keys rotate \
              --api-key 'My API Key' \
              --workspace-id workspace_01HXKD2E5NQM3T9AYWCF133E3Q \
              --id apikey_01HXKD2E5NQM3T9AYWCFCSPNQY
components:
  schemas:
    RotateAPIKeyRequest:
      type: object
      properties:
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: The workspace the API key belongs to (path).
        id:
          readOnly: true
          example: apikey_01HXKD2E5NQM3T9AYWCFCSPNQY
          type: string
          description: >-
            The API key to rotate. A new token is issued and any existing token
            is
             invalidated.
    APIKey:
      required:
        - metadata
        - spec
        - state
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/APIKeySpec'
        info:
          $ref: '#/components/schemas/APIKeyInfo'
        state:
          readOnly: true
          enum:
            - STATE_UNSPECIFIED
            - STATE_ENABLED
            - STATE_DISABLED
          type: string
          description: |-
            The current lifecycle state of the API key. Output only. Keys are
             created STATE_ENABLED; use the :disable and :enable actions to
             transition between states.
          format: enum
      description: >-
        An API key. Every key belongs to exactly one workspace and is managed
        via
         the workspace-scoped API key routes. The only exception is the
         system-managed global account key, which spans all workspaces and is
         managed via the account global_api_key routes.
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    AccountResourceMetadata:
      required:
        - id
        - accountId
        - name
        - profileId
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "apikey_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
        createdAt:
          readOnly: true
          type: string
          format: date-time
      description: >-
        AccountResourceMetadata is used to represent a resource that is
        associated to an account but not to a workspace.
    APIKeySpec:
      type: object
      properties:
        token:
          readOnly: true
          type: string
          description: >-
            The bearer token used to authenticate as this API key. Returned only
            on
             creation and rotation; subsequent reads omit this field.
        description:
          type: string
          description: Free-form description of what this API key is used for.
        permissions:
          type: array
          items:
            type: string
          description: |-
            Scopes granted to this key. Each entry is a colon-separated
             resource:verb string (e.g. "objectives:manage").

             Resources: agents, objectives, tools, memory, api_keys, workspaces,
             widgets, widget_sessions, secrets, account.
             Verbs: read and manage, where manage implies read — a stored scope set
             is normalized to drop "x:read" when "x:manage" is present. The secrets
             and account resources support only manage. "*" is an explicit
             full-access grant.

             Scopes are deny-by-default: a key with an empty list can call only
             scope-free endpoints. Full access is always an explicit "*" grant.
        system:
          readOnly: true
          type: boolean
          description: >-
            True when this key is managed by the system (i.e. the
            auto-provisioned
             global account key). System keys cannot be deleted but can be rotated.
      description: Configuration for an API key.
    APIKeyInfo:
      type: object
      properties:
        createdBy:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/Profile'
          description: The profile that created the key.
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
    Profile:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/ProfileSpec'
      description: |-
        A profile identifies a user or non-human principal (such as an API key)
         at the account level. Profiles are account-scoped and can be granted access
         to multiple workspaces.
    ProfileSpec:
      required:
        - type
      type: object
      properties:
        email:
          type: string
          description: >-
            Email address of the profile. Required and unique within an account
            for
             user profiles.
        name:
          type: string
          description: Display name (e.g., "Bobby Tables").
        type:
          enum:
            - PROFILE_TYPE_UNSPECIFIED
            - PROFILE_TYPE_USER
            - PROFILE_TYPE_API_KEY
            - PROFILE_TYPE_SYSTEM
          type: string
          description: >-
            Whether this profile represents a human user, an API key, or a
            system
             principal.
          format: enum
      description: Configuration for a profile.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````