> ## Documentation Index
> Fetch the complete documentation index at: https://support.lilt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate an API key

> Replace the prefix and secret of an existing API key, invalidating the previous secret and returning a new plaintext secret. The key's name and expiry are preserved.

The new secret is shown exactly once. Revoked keys cannot be rotated. The caller must own the key or hold `apiKey.write` on the current organization. The request body must be empty.




## OpenAPI

````yaml /api-reference/openapi-bundled.yaml post /v2/api-keys/{id}/rotate
openapi: 3.0.3
info:
  title: LILT API
  description: >
    LILT API Support: https://lilt.atlassian.net/servicedesk/customer/portals


    The LILT API enables programmatic access to the full-range of LILT backend
    services including:
      * Training of and translating with interactive, adaptive machine translation
      * Large-scale translation memory
      * The Lexicon (a large-scale termbase)
      * Programmatic control of the LILT CAT environment
      * Translation memory synchronization


    Requests and responses are in JSON format. The REST API only responds to
    HTTPS / SSL requests.


    The base url for this REST API is `https://api.lilt.com/`.


    ## Authentication


    Requests are authenticated via API key, which requires the Business plan.


    Requests are authenticated using [HTTP Basic
    Auth](https://en.wikipedia.org/wiki/Basic_access_authentication). Add your
    API key as both the `username` and `password`.


    For development, you may also pass the API key via the `key` query
    parameter. This is less secure than HTTP Basic Auth, and is not recommended
    for production use.


    ## Quotas


    Our services have a general quota of 4000 requests per minute. Should you
    hit the maximum requests per minute, you will need to wait 60 seconds before
    you can send another request.
  version: v3.0.3
  license:
    name: LILT Platform Terms and Conditions
    url: https://lilt.com/lilt-platform-terms-and-conditions
servers:
  - url: https://api.lilt.com
security:
  - BasicAuth: []
  - ApiKeyAuth: []
paths:
  /v2/api-keys/{id}/rotate:
    post:
      tags:
        - API Keys
      summary: Rotate an API key
      description: >
        Replace the prefix and secret of an existing API key, invalidating the
        previous secret and returning a new plaintext secret. The key's name and
        expiry are preserved.


        The new secret is shown exactly once. Revoked keys cannot be rotated.
        The caller must own the key or hold `apiKey.write` on the current
        organization. The request body must be empty.
      operationId: rotateApiKey
      parameters:
        - name: id
          in: path
          required: true
          description: The API key's unique identifier.
          schema:
            type: string
      responses:
        '200':
          description: The rotated API key with its new plaintext secret (shown once only).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyWithSecret'
        '400':
          description: >-
            The key has already been revoked and cannot be rotated, a non-empty
            request body was sent, or the authenticated user has no active
            organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyError'
        '401':
          description: The request is not authenticated.
        '403':
          description: The caller does not own the key and lacks `apiKey.write`.
        '404':
          description: API key not found, or belongs to another organization.
        default:
          description: Unexpected error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ApiKeyWithSecret:
      type: object
      description: >-
        A newly created or rotated API key, including the plaintext secret. The
        secret is shown exactly once and cannot be retrieved again. Note that
        `lastUsedAt` and `revokedAt` are not returned by the create and rotate
        operations.
      required:
        - id
        - name
        - prefix
        - key
        - createdAt
      properties:
        id:
          type: string
          description: The unique identifier for the API key.
          example: uuid-1234
        name:
          type: string
          description: A human-readable label for the key.
          example: CI bot
        prefix:
          type: string
          description: >-
            The first 8 characters of the key's random portion — the part that
            follows the `lilt_` prefix. Safe to display.
          example: aaaaaaaa
        key:
          type: string
          description: >-
            The full plaintext API key (`lilt_` followed by 40 hex characters).
            Shown once only.
          example: lilt_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
        createdAt:
          type: string
          format: date-time
          description: ISO-8601 timestamp when the key was created.
          example: '2026-04-29T00:00:00Z'
        expiresAt:
          type: string
          format: date-time
          nullable: true
          description: >-
            ISO-8601 timestamp when the key expires, or null if it does not
            expire.
          example: '2027-01-01T00:00:00Z'
        ownerEmail:
          type: string
          nullable: true
          description: >-
            Email address of the user who owns the key. Returned when creating a
            key; omitted when rotating one.
          example: developer@lilt.com
        ownerUserId:
          type: integer
          nullable: true
          description: >-
            Numeric identifier of the user who owns the key. Returned when
            creating a key; omitted when rotating one.
          example: 42
    ApiKeyError:
      type: object
      description: >-
        Error response returned by the API Keys endpoints. The human-readable
        message is carried in the `error` field.
      properties:
        error:
          type: string
          description: A human-readable message describing the error.
          example: No active organization
    Error:
      type: object
      properties:
        message:
          type: string
          description: A human-readable message describing the error.
      description: |
        Response in the event of an unexpected error.
      example:
        message: Internal server error.
  securitySchemes:
    BasicAuth:
      type: http
      scheme: basic
    ApiKeyAuth:
      type: apiKey
      name: key
      in: query

````