Replace keys
Changes what a key is called, what it may reach, when it expires, or revokes it.
PUT /v1/iam/keys/{owner}/{name}
| Address | https://api.hanzo.ai/v1/iam/keys/{owner}/{name} |
| Method | PUT |
| Operation | put_iam_keys_by_owner_by_name |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Changes what a key is called, what it may reach, when it expires, or revokes it. The credential itself is not reissued — the key in your deployment keeps working until it expires or is revoked.
An update writes the whole set of editable fields, so send the key as you read it with your changes made. The class in its scope (publishable or secret) is fixed at creation and an update naming the other is refused. Setting state to "Revoked" revokes the key: the row stays, records who revoked it and when, and is never updated again.
Request
26 fields, body application/json (required).
| Field | In | Type | Required | Description |
|---|---|---|---|---|
owner | path | string | yes | Owner is the tenant that holds the key; Name is unique within Owner. |
name | path | string | yes | |
accessKey | body | string | — | AccessKey (pk-) is the publishable identifier and lookup index; AccessSecret (sk-) is the confidential secret. |
accessSecret | body | string | — | |
accessSecretDigest | body | string | — | AccessSecretDigest is how a presented secret finds its key: the resolver digests what the caller sent and looks THAT up. |
act | body | boolean | — | Act is the durable, opt-in grant that lets this key act FOR a user in its own org — the credential behind as(): presenting it authorizes minting a short-lived, user-bound token for a member of the key's tenant. |
application | body | string | — | |
createdAt | body | string (date-time) | — | |
createdTime | body | string | — | CreatedTime and UpdatedTime are RFC3339 audit stamps carried as strings for byte-parity with the v1 row (orm.Model separately tracks CreatedAt / UpdatedAt as time.Time for the store's own lifecycle). |
deleted | body | boolean | — | |
displayName | body | string | — | DisplayName is the human-facing label. |
expireTime | body | string | — | ExpireTime is when the key stops being honored (empty = never). |
id | body | string | — | |
name | body | string | — | |
organization | body | string | — | |
owner | body | string | — | Owner is the tenant that holds the key; Name is unique within Owner. |
prefix | body | string | — | Prefix is the head of the credential the holder presents — the sk- of a secret key, the pk- of a publishable one — recorded when the key is minted (PrefixOf). |
revokeTime | body | string | — | |
revoker | body | string | — | Revoker is who revoked the key and RevokeTime when. |
scope | body | string | — | Scope is the key's ACCESS CLASS, orthogonal to Type (which names the bound principal). |
state | body | string | — | |
type | body | string | — | Type is the scope the key is bound to — "Organization", "Application", "User", or "General" — and Organization / Application / User name the concrete principal for whichever scope Type selects. |
updatedAt | body | string (date-time) | — | |
updatedTime | body | string | — | |
usedTime | body | string | — | UsedTime is when the key was last presented and resolved. |
user | body | string | — |
Response
| Status | Body | Meaning |
|---|---|---|
200 | iam.Key | ok |
202 | Approval | held for approval |
default | problem-details | refused |
200 body — 24 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
accessKey | body | string | — | AccessKey (pk-) is the publishable identifier and lookup index; AccessSecret (sk-) is the confidential secret. |
accessSecret | body | string | — | |
accessSecretDigest | body | string | — | AccessSecretDigest is how a presented secret finds its key: the resolver digests what the caller sent and looks THAT up. |
act | body | boolean | — | Act is the durable, opt-in grant that lets this key act FOR a user in its own org — the credential behind as(): presenting it authorizes minting a short-lived, user-bound token for a member of the key's tenant. |
application | body | string | — | |
createdAt | body | string (date-time) | — | |
createdTime | body | string | — | CreatedTime and UpdatedTime are RFC3339 audit stamps carried as strings for byte-parity with the v1 row (orm.Model separately tracks CreatedAt / UpdatedAt as time.Time for the store's own lifecycle). |
deleted | body | boolean | — | |
displayName | body | string | — | DisplayName is the human-facing label. |
expireTime | body | string | — | ExpireTime is when the key stops being honored (empty = never). |
id | body | string | — | |
name | body | string | — | |
organization | body | string | — | |
owner | body | string | — | Owner is the tenant that holds the key; Name is unique within Owner. |
prefix | body | string | — | Prefix is the head of the credential the holder presents — the sk- of a secret key, the pk- of a publishable one — recorded when the key is minted (PrefixOf). |
revokeTime | body | string | — | |
revoker | body | string | — | Revoker is who revoked the key and RevokeTime when. |
scope | body | string | — | Scope is the key's ACCESS CLASS, orthogonal to Type (which names the bound principal). |
state | body | string | — | |
type | body | string | — | Type is the scope the key is bound to — "Organization", "Application", "User", or "General" — and Organization / Application / User name the concrete principal for whichever scope Type selects. |
updatedAt | body | string (date-time) | — | |
updatedTime | body | string | — | |
usedTime | body | string | — | UsedTime is when the key was last presented and resolved. |
user | body | string | — |
Failure carries the platform error shape — see Errors.
Examples
hanzo iam keys owner set <owner> <name>import { Configuration, IamApi } from 'hanzoai';
const api = new IamApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.putIamKeysByOwnerByName({ owner: 'owner', name: 'name', accessKey: "<accessKey>", accessSecret: "<accessSecret>" });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import IamApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = IamApi(client).put_iam_keys_by_owner_by_name(owner='owner', name='name', access_key="<accessKey>", access_secret="<accessSecret>")cfg := hanzoai.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := hanzoai.NewAPIClient(cfg)
resp, _, err := client.IamAPI.PutIamKeysByOwnerByName(context.Background()).Execute()
if err != nil {
return err
}use hanzo_client::apis::{configuration::Configuration, iam_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = iam_api::put_iam_keys_by_owner_by_name(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.IamApi;
ApiClient client = new ApiClient();
client.setBearerToken(System.getenv("HANZO_API_KEY"));
var result = new IamApi(client).putIamKeysByOwnerByName();curl -X PUT https://api.hanzo.ai/v1/iam/keys/<owner>/<name> \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"accessKey": "<accessKey>",
"accessSecret": "<accessSecret>"
}'MCP reaches iam through the iam tool, which names its 44 operations with its own verbs — this one among them, under a name only MCP declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "list_iam_applications"
}
}
}'