Update keys
Changes one key's name, permissions, budget, rate or expiry.
PATCH /v1/account/keys/{id}
| Address | https://api.hanzo.ai/v1/account/keys/{id} |
| Method | PATCH |
| Operation | patch_account_keys_by_id |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Changes one key's name, permissions, budget, rate or expiry. The secret is not reissued: the key in your deployment keeps working, under its new policy. Only the person the key belongs to may edit it, and a revoked key cannot be edited.
Request
9 fields, body application/json (required).
| Field | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | ID is the key to edit, from the path. |
budget | body | account.keyBudget | — | |
budget.month | body | integer (int64) | — | Month is per calendar month, UTC. |
budget.total | body | integer (int64) | — | Total is over the key's whole life. |
expires | body | string | — | Expires replaces when the key stops working, RFC 3339. |
id | body | string | — | ID is the key to edit, from the path. |
limit | body | string[] | — | Limit replaces what the key may reach. |
name | body | string | — | Name relabels the key. |
rate | body | integer (int64) | — | Rate replaces the key's requests a minute; zero drops the limit. |
Response
| Status | Body | Meaning |
|---|---|---|
200 | account.apiKey | ok |
default | problem-details | refused |
200 body — 20 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
budget | body | account.keyBudget | — | |
budget.month | body | integer (int64) | — | Month is per calendar month, UTC. |
budget.total | body | integer (int64) | — | Total is over the key's whole life. |
created | body | string | — | Created is when the key was minted (RFC 3339). |
creator | body | string | — | Creator is the person the key speaks for, <org>/<user>: who created it. |
expires | body | string | — | Expires is when the key stops working (RFC 3339). |
id | body | string | — | ID addresses this key in PATCH and DELETE /v1/account/keys/{id}. |
key | body | string | — | Key is the full credential. |
limit | body | string[] | — | Limit is what this key may reach, as kind:name entries — model:zen5, project:acme, product:train (read and write), read:billing (read only), read:* (a read-only key). |
name | body | string | — | Name is the key's label, chosen by the person who made it. |
prefix | body | string | — | Prefix is the head of the credential this key's holder presents — the sk- of a secret key — enough to tell which string a row is, never enough to use. |
rate | body | integer (int64) | — | Rate is how many requests a minute the key may make. |
revoked | body | string | — | |
revoker | body | string | — | Revoker is who revoked the key, <org>/<user>, and Revoked when. |
spend | body | account.keyBudget | — | |
spend.month | body | integer (int64) | — | Month is per calendar month, UTC. |
spend.total | body | integer (int64) | — | Total is over the key's whole life. |
status | body | string | — | Status is active, expired, revoked, or disabled (switched off in IAM). |
type | body | string | — | Type is the key class: secret (sk-) or publishable (pk-). |
used | body | string | — | Used is when the key was last used (RFC 3339). |
Failure carries the platform error shape — see Errors.
Examples
CLI
SDK
HTTP
MCP
hanzo has no subcommand for this operation — the CLI serves only what cloud's live route table confirms. Use HTTP or an SDK.
.ts
.py
.go
.rs
.java
import { Configuration, AccountApi } from 'hanzoai';
const api = new AccountApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.patchAccountKeysById({ id: 'id', budget: {"month":0,"total":0}, expires: "<expires>" });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import AccountApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = AccountApi(client).patch_account_keys_by_id(id='id', budget={"month":0,"total":0}, expires="<expires>")cfg := hanzoai.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := hanzoai.NewAPIClient(cfg)
resp, _, err := client.AccountAPI.PatchAccountKeysById(context.Background()).Execute()
if err != nil {
return err
}use hanzo_client::apis::{configuration::Configuration, account_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = account_api::patch_account_keys_by_id(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.AccountApi;
ApiClient client = new ApiClient();
client.setBearerToken(System.getenv("HANZO_API_KEY"));
var result = new AccountApi(client).patchAccountKeysById();curl -X PATCH https://api.hanzo.ai/v1/account/keys/<id> \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"budget": {
"month": 0,
"total": 0
},
"expires": "<expires>"
}'MCP reaches account through the account tool, which names its 6 operations with its own verbs — this one among them, under a name only MCP declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "get_account_appearance"
}
}
}'Was this page useful?