Rotate an API key
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"grace_hours": 24
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({grace_hours: 24})
};
fetch('https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate"
payload = { "grace_hours": 24 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"key": {
"id": "f0c8a1d3-5b7e-4296-8d4a-2e6b9c1f7a35",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Back office (test)",
"prefix": "sk_test_Qx9m",
"scopes": "kyc:extract,kyc:verify",
"bound_identity": null,
"status": "active",
"last_used_at": null,
"expires_at": null,
"created_at": "2026-10-07T09:14:22Z"
},
"raw_key": "sk_test_Qx9m...redacted",
"previous": {
"id": "9a2e6c4b-8d1f-4b57-9c3a-5e7f1d0b2a68",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Back office (test)",
"prefix": "sk_test_Ab3d",
"scopes": "kyc:extract,kyc:verify",
"bound_identity": null,
"status": "active",
"last_used_at": null,
"expires_at": "2026-10-08T09:14:22Z",
"created_at": "2026-10-07T09:14:22Z"
}
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "No active API key with that id"
}{
"detail": {
"code": "key_already_rotated",
"message": "This key was already rotated and its successor is live; it expires at 2026-10-08T09:14:22+00:00. Use the successor, or create a new key."
}
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Rotate an API key
Who can call it: tenant_admin, tenant_api_manager or platform_admin.
Issues a successor with the same scopes (its secret is in this response only). The old key keeps working for grace_hours (default 24, at most 168), then expires. Rotating a key that was already rotated is 409 key_already_rotated.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Rotate an API key
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"grace_hours": 24
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({grace_hours: 24})
};
fetch('https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/api-keys/{key_id}/rotate"
payload = { "grace_hours": 24 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"key": {
"id": "f0c8a1d3-5b7e-4296-8d4a-2e6b9c1f7a35",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Back office (test)",
"prefix": "sk_test_Qx9m",
"scopes": "kyc:extract,kyc:verify",
"bound_identity": null,
"status": "active",
"last_used_at": null,
"expires_at": null,
"created_at": "2026-10-07T09:14:22Z"
},
"raw_key": "sk_test_Qx9m...redacted",
"previous": {
"id": "9a2e6c4b-8d1f-4b57-9c3a-5e7f1d0b2a68",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Back office (test)",
"prefix": "sk_test_Ab3d",
"scopes": "kyc:extract,kyc:verify",
"bound_identity": null,
"status": "active",
"last_used_at": null,
"expires_at": "2026-10-08T09:14:22Z",
"created_at": "2026-10-07T09:14:22Z"
}
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "No active API key with that id"
}{
"detail": {
"code": "key_already_rotated",
"message": "This key was already rotated and its successor is live; it expires at 2026-10-08T09:14:22+00:00. Use the successor, or create a new key."
}
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Autorisations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.
Paramètres de chemin
Corps
application/json
Plage requise:
0 <= x <= 168