Skip to main content
PATCH
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

id
string
required

The apiKeyId from a listing, not the token and not the keyId.

Body

application/json

At least one of the fields; omitted fields keep their stored values.

name
string

A new label.

Required string length: 1 - 120
scopes
enum<string>[]

A non empty subset of the scopes the key currently holds.

Minimum array length: 1

A scope to keep.

Available options:
devices:read,
devices:act,
devices:lease,
runs:start,
orders:place,
apps:read,
apps:write,
apps:delete
deviceIds
string[]

A non empty subset of the key's current device set (or of the org's devices, for a whole-org key).

Required array length: 1 - 200 elements
ttlMs
integer

New lifetime in milliseconds, measured from now. At most 3650 days per renewal.

Required range: 1 <= x <= 315360000000

Response

The updated key summary (never the token).

A stored key, as a listing returns it. The secret is not part of it and cannot be recovered.

apiKeyId
string
required

The key's own id. This is what you pass to revoke it.

keyId
string
required

The public half of the token, the part before the secret.

name
string
required
scopes
enum<string>[]
required

A granted scope.

Available options:
devices:read,
devices:act,
devices:lease,
runs:start,
orders:place,
apps:read,
apps:write,
apps:delete
deviceIds
string[] | null
required

The device subset this key may see and address, or null for the whole org.

createdBy
string
required
createdAt
string<date-time>
required
expiresAt
string<date-time> | null
required
revokedAt
string<date-time> | null
required
lastUsedAt
string<date-time> | null
required

Updated off the request path, so it can lag slightly behind the last real use.

rotatedFrom
string | null
required

The apiKeyId this key replaced via rotation, or null for keys minted directly.