TokenLab

Management

Update API Key

Update an API key in the current Workspace.

PATCHhttps://api.tokenlab.sh/v1/management/api-keys/{keyId}

Overview

Use this endpoint to update the name, usage limit, allowed models, expiry, or status of an existing user API key.

Request Body

At least one field must be provided.

FieldTypeDefault / LimitsNotes
statusenum-active, inactive, revoked
namestringlength 1-50Updated display name
limitAmountnumber | string | null0–100000 USDnull means unlimited; 0 prevents spend. Decimal strings support up to 6 decimal places.
limitCurrencyenumdefault USDUSD only. Sending CNY returns 400 currency_retired. When set, limitAmount is required.
modelsstring[]-Updated model allowlist
deliveryPolicystring | nullauto, verified, official, nullnull inherits the Workspace delivery policy.
expiresAtstring | nullRFC3339 datetimenull clears the expiry

Notes

  • Monetary fields are USD-only. CNY inputs are retired and return 400 currency_retired.

  • The Management API does not provide deletion. Use inactive for a temporary pause and revoked to retire a key permanently.

  • Replace a revoked key with a new one.

Example

Request

cURL
curl -X PATCH "https://api.tokenlab.sh/v1/management/api-keys/key_abc123def456" \
  -H "Authorization: Bearer mt-your-management-token" \
  -H "Content-Type: application/json" \
  -d '{
    "status": "inactive",
    "limitAmount": 0
  }'

Request / Response

This page provides the OpenAPI schema and copyable request examples. Send management requests from your terminal or client with a Management Token; direct sending is not available on this page.

Response example

Response

200 OK
{
  "id": "key_abc123def456",
  "name": "Backend Worker",
  "key_prefix": "sk-live...",
  "status": "inactive",
  "limit_amount": 0,
  "limit_amount_decimal": "0",
  "used_amount": 148.25,
  "used_amount_decimal": "148.25",
  "models": [
    "gpt-5.6-luna",
    "claude-3-7-sonnet"
  ],
  "expires_at": "2026-12-31T23:59:59.000Z",
  "last_used_at": "2026-07-08T03:12:45.000Z",
  "created_at": "2026-07-01T10:00:00.000Z",
  "delivery_policy": null
}

Important fields

idstring
API key identifier used in follow-up Management API calls.
namestring
Display name for the API key.
key_prefixstring
Non-secret key prefix for display and support.
statusstring
One of active, inactive, suspended, or revoked.
limit_amountnumber | null
Spending cap in USD as a JSON number for display. null means unlimited.
limit_amount_decimalstring | null
Exact spending cap in USD as a decimal string. null means unlimited.
used_amountnumber
Accumulated usage in USD as a JSON number for display.
used_amount_decimalstring
Exact accumulated usage in USD as a decimal string.
modelsstring[]
Per-key model allowlist. Empty array means no additional key-level model restriction.
delivery_policystring | null
auto, verified, official, null. null inherits the Workspace delivery policy.
expires_atstring | null
ISO timestamp when the key expires, or null for no expiry.
last_used_atstring | null
ISO timestamp for the most recent use, or null when unused.
created_atstring
ISO creation timestamp.

Authorization

ManagementTokenAuth
AuthorizationBearer <token>

Management token authentication. Create or manage Management Tokens in Dashboard > API > Management Tokens.

In: header

Path Parameters

keyId*string

Request Body

application/json

At least one field must be provided.

Properties1 <= properties

Response

application/json

application/json

application/json

application/json

application/json

application/json