Skip to main content
PATCH
JavaScript

Authorizations

Authorization
string
header
required

An Account API key, account-scoped JWT, App API key, or user OAuth token. Prepend the key or token with Bearer, for example Bearer ***************************.

Headers

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-08-21"

Path Parameters

id
string
required

API key ID, prefixed apik_.

Body

application/json
api_version_date
enum<string>

Dated API version used when requests authenticated with this key omit the Api-Version-Date header. New keys default to the latest version.

Available options:
2025-01-01,
2026-06-08,
2026-06-09,
2026-06-20,
2026-07-01,
2026-07-08,
2026-07-08-1,
2026-07-18,
2026-07-20,
2026-07-22,
2026-07-23,
2026-07-25,
2026-07-26,
2026-07-27,
2026-07-29,
2026-07-29-1,
2026-07-31,
2026-08-03,
2026-08-05,
2026-08-05-1,
2026-08-10,
2026-08-12,
2026-08-13,
2026-08-14,
2026-08-21
Example:

"2026-08-21"

expires_at
string | null

When the API key should stop working, as an ISO 8601 timestamp. Omit (or pass null on update) for a key that never expires.

Example:

"2026-01-01T12:00:00.000Z"

ip_allowlist
string[] | null

IPv4/IPv6 CIDR ranges allowed to use this key, for example ["203.0.113.0/24"]. Empty or null allows any IP.

name
string | null

A new human-readable name for the API key.

Example:

"Shine Time Booking (staging)"

permissions
object

The permissions policy for the API key: explicit permission statements, or a system role to inherit from. Statements without a resources array default to the owning account (Account API keys) or every key-addressable resource (App API keys).

Response

api key updated

api_version_date
enum<string>
required

Dated API version used when requests authenticated with this key omit the Api-Version-Date header.

Available options:
2025-01-01,
2026-06-08,
2026-06-09,
2026-06-20,
2026-07-01,
2026-07-08,
2026-07-08-1,
2026-07-18,
2026-07-20,
2026-07-22,
2026-07-23,
2026-07-25,
2026-07-26,
2026-07-27,
2026-07-29,
2026-07-29-1,
2026-07-31,
2026-08-03,
2026-08-05,
2026-08-05-1,
2026-08-10,
2026-08-12,
2026-08-13,
2026-08-14,
2026-08-21
Example:

"2026-08-21"

created_at
string
required

When the API key was created, as an ISO 8601 timestamp.

Example:

"2026-01-01T12:00:00.000Z"

expires_at
string | null
required

When the API key stops working, as an ISO 8601 timestamp. null means it never expires.

Example:

"2026-01-01T12:00:00.000Z"

id
string
required

API key ID, prefixed apik_.

Example:

"apik_xxxxxxxxxxxxxx"

ip_allowlist
string[] | null
required

IPv4/IPv6 CIDR ranges allowed to use this key. null or empty means requests are accepted from any IP.

is_default_for_resource
boolean
required

Whether this is the resource's default API key. Default keys cannot be updated or deleted, only rotated.

Example:

false

name
string | null
required

Human-readable name identifying the API key, or null when none was set.

Example:

"Shine Time Booking (admin role)"

obfuscated_secret_key
string
required

Masked version of the secret key, so the key can be recognized without revealing the full secret.

Example:

"apik_xxxx....xxxx"

system_role
enum<string> | null
required

System role the key inherits its permissions from, or null when it uses an explicit permissions policy. Only account API keys can use a system role.

Available options:
owner,
admin,
moderator,
sales_manager,
advertiser,
null
Example:

"admin"

updated_at
string
required

When the API key was last updated, as an ISO 8601 timestamp.

Example:

"2026-01-01T12:00:00.000Z"

grants
object[]
secret_key
string

The full secret used to authenticate requests. Returned only once, on create and rotate responses — store it immediately.

Example:

"apik_xxxxxxxxxxxxxx_C0000_C_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"