Docs

PATCH /api-keys/{id}

Rename a key or change its domain scope and scopes. The token is unchanged — use POST /api-keys/:id/rotate for that.

Parameters

  • id path · string · required
  • Idempotency-Key header · string · optionalMakes this call safe to retry. Send the same key with the same body and the original response is replayed instead of the work happening twice. Keys are 1-256 characters and are remembered for 7 days. While the first attempt is still running, a second call with that key returns 409 idempotency_in_flight (Resend calls this concurrent_idempotent_requests); the same key with a different body returns 409 idempotency_payload_mismatch (Resend: invalid_idempotent_request).

Request body

FieldTypeRequiredNotes
domain_scopestring | nullno
namestringno
scopesarray<"emails:send" | "emails:read" | "domains:read" | "domains:write" | "webhooks:read" | "webhooks:write" | …>no

Responses

  • 200 Success
  • 400 Validation error
  • 401 Missing API key
  • 403 Forbidden
  • 404 Not found
  • 409 Conflict
  • 429 Rate limited
  • 500 Internal server error

Response headers

  • ratelimit-limit — Messages this API key may spend in one 60-second window.
  • ratelimit-remaining — Messages left in the current window.
  • ratelimit-reset — Seconds until the current window resets and the budget refills.

200 body

FieldTypeRequiredNotes
budget_per_periodinteger | nullyes
created_atstringyes
domain_scopestring | nullyes
expires_atstring | nullyes
idstringyes
last_used_atstring | nullyes
namestringyes
period"hourly" | "daily" | "monthly"yes
permission"full_access" | "sending_access"yes
previous_key_expires_atstring | nullyes
rate_ceiling_per_minuteinteger | nullyes
request_count_30dintegeryes
rotated_atstring | nullyes
scopesarray<string>yes
systembooleanyes
token_prefixstringyes

Errors

Codes in the catalogue that answer with one of this operation’s error statuses. Every one of them carries a fix.