Spoar
Projects

Rotate a key

POST
/v2/projects/{project}/keys

Replaces the public or the secret key. A new secret key is returned once and the old one stops working.

Authorization

AuthorizationBearer <token>

An API token from POST /v2/tokens (at_live_...), or a project's secret key (sk_...) for server-side ingest.

In: header

Path Parameters

project*string

The project id, as listed by GET /v2/projects.

Length1 <= length

Request Body

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v2/projects/string/keys" \  -H "Content-Type: application/json" \  -d '{    "kind": "secret"  }'
{  "data": {    "kind": "secret",    "key": "sk_live_9b8a7f6e5d4c3b2a1f0e",    "rotatedAt": "2026-09-27T16:43:00.000Z"  }}