Update keys

Changes one key's name, permissions, budget, rate or expiry.

PATCH /v1/account/keys/{id}

Addresshttps://api.hanzo.ai/v1/account/keys/{id}
MethodPATCH
Operationpatch_account_keys_by_id
AuthAuthorization: Bearer $HANZO_API_KEY

Changes one key's name, permissions, budget, rate or expiry. The secret is not reissued: the key in your deployment keeps working, under its new policy. Only the person the key belongs to may edit it, and a revoked key cannot be edited.

Request

9 fields, body application/json (required).

FieldInTypeRequiredDescription
idpathstringyesID is the key to edit, from the path.
budgetbodyaccount.keyBudget—
budget.monthbodyinteger (int64)—Month is per calendar month, UTC.
budget.totalbodyinteger (int64)—Total is over the key's whole life.
expiresbodystring—Expires replaces when the key stops working, RFC 3339.
idbodystring—ID is the key to edit, from the path.
limitbodystring[]—Limit replaces what the key may reach.
namebodystring—Name relabels the key.
ratebodyinteger (int64)—Rate replaces the key's requests a minute; zero drops the limit.

Response

StatusBodyMeaning
200account.apiKeyok
defaultproblem-detailsrefused

200 body — 20 fields.

FieldInTypeAlwaysDescription
budgetbodyaccount.keyBudget—
budget.monthbodyinteger (int64)—Month is per calendar month, UTC.
budget.totalbodyinteger (int64)—Total is over the key's whole life.
createdbodystring—Created is when the key was minted (RFC 3339).
creatorbodystring—Creator is the person the key speaks for, <org>/<user>: who created it.
expiresbodystring—Expires is when the key stops working (RFC 3339).
idbodystring—ID addresses this key in PATCH and DELETE /v1/account/keys/{id}.
keybodystring—Key is the full credential.
limitbodystring[]—Limit is what this key may reach, as kind:name entries — model:zen5, project:acme, product:train (read and write), read:billing (read only), read:* (a read-only key).
namebodystring—Name is the key's label, chosen by the person who made it.
prefixbodystring—Prefix is the head of the credential this key's holder presents — the sk- of a secret key — enough to tell which string a row is, never enough to use.
ratebodyinteger (int64)—Rate is how many requests a minute the key may make.
revokedbodystring—
revokerbodystring—Revoker is who revoked the key, <org>/<user>, and Revoked when.
spendbodyaccount.keyBudget—
spend.monthbodyinteger (int64)—Month is per calendar month, UTC.
spend.totalbodyinteger (int64)—Total is over the key's whole life.
statusbodystring—Status is active, expired, revoked, or disabled (switched off in IAM).
typebodystring—Type is the key class: secret (sk-) or publishable (pk-).
usedbodystring—Used is when the key was last used (RFC 3339).

Failure carries the platform error shape — see Errors.

Examples

hanzo has no subcommand for this operation — the CLI serves only what cloud's live route table confirms. Use HTTP or an SDK.

import { Configuration, AccountApi } from 'hanzoai';

const api = new AccountApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.patchAccountKeysById({ id: 'id', budget: {"month":0,"total":0}, expires: "<expires>" });
from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import AccountApi

client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = AccountApi(client).patch_account_keys_by_id(id='id', budget={"month":0,"total":0}, expires="<expires>")
cfg := hanzoai.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := hanzoai.NewAPIClient(cfg)

resp, _, err := client.AccountAPI.PatchAccountKeysById(context.Background()).Execute()
if err != nil {
	return err
}
use hanzo_client::apis::{configuration::Configuration, account_api};

let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();

let result = account_api::patch_account_keys_by_id(&cfg, Default::default()).await?;
import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.AccountApi;

ApiClient client = new ApiClient();
client.setBearerToken(System.getenv("HANZO_API_KEY"));

var result = new AccountApi(client).patchAccountKeysById();
curl -X PATCH https://api.hanzo.ai/v1/account/keys/<id> \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "budget": {
         "month": 0,
         "total": 0
       },
       "expires": "<expires>"
     }'

MCP reaches account through the account tool, which names its 6 operations with its own verbs — this one among them, under a name only MCP declares. describe explains any of them:

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "describe",
         "arguments": {
           "op": "get_account_appearance"
         }
       }
     }'

Account API · All Hanzo APIs · Interactive reference

Was this page useful?