keys.updateKey, or add and remove them with six dedicated endpoints. Changes take about 10 seconds to reach verification. Verifying keys describes that timing.
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as
Authorization: Bearer <root key>. See Permission reference for every permission.api.*.update_key or api.<api_id>.update_key (creation needs create_key). Four of the incremental endpoints also need the matching rbac.* action: add_permission_to_key for keys.addPermissions, remove_permission_from_key for keys.removePermissions, both for keys.setPermissions, and add_role_to_key for keys.addRoles. keys.removeRoles and keys.setRoles need nothing beyond update_key.
keys.addPermissions and keys.setPermissions only create a new permission slug if the root key also has rbac.*.create_permission. Without it, an unknown slug fails with HTTP 403 err:unkey:authorization:insufficient_permissions. (keys.createKey and keys.updateKey create new slugs without that permission.) Roles are never created for you. An unknown role fails with HTTP 404 err:unkey:data:role_not_found.
At creation
keys.createKey accepts roles (up to 100 names, each 1 to 128 characters) and permissions (up to 1000 slugs, each 1 to 128 characters matching ^[a-zA-Z0-9_:\-\.\*]+$).
Replace everything
keys.updateKey takes the same two fields. Sending a list replaces it in full. Leaving a field out keeps it as it is.
Adjust incrementally
Each endpoint takeskeyId and an array of permission slugs or role names (not IDs). The add and remove endpoints need at least one entry, so [] fails with HTTP 400. Send [] to keys.setPermissions or keys.setRoles to remove everything.
authorization.connect_permission_and_key and authorization.disconnect_role_and_key, so you can see the history of a key’s access.
Direct permissions versus roles
Removing a permission from a key doesn’t help if one of its roles also grants it. To take a permission away completely, remove it from the key and from the key’s roles, or remove the role. To change what a role contains, callpermissions.setRolePermissions. That changes every key with the role. See Roles and permissions.