Rotate Admin Key
Mint a successor, then shorten the predecessor to a grace window (§7).
Both keys work during the overlap — rotation is not revocation, which is immediate and has no grace.
Re-checks the caller’s CURRENT authority against the predecessor’s own
scope/permissions, exactly like create — the route floor alone (default
SELF) is not enough: a caller demoted since minting an ORG-scoped key
would otherwise still find it via created_by and rotate it into a
fresh 90-day ORG-scoped credential nobody would let them create today.
Authorizations
Enter your MeshAPI key (rsk_...) or, for the admin-keys endpoints, a dashboard session token — sent as Authorization: Bearer <token>.
Headers
Dated version of the API contract to pin this request to. Omit it and the request is served under 2026-08 — the oldest supported version, so an existing integration is never moved by a release. A malformed or unsupported value is rejected with 400 invalid_api_version rather than falling back silently. The version actually served is echoed as X-Mesh-Version on every response, including errors.
2026-08 Path Parameters
Body
Response
Successful Response
What a member of an organisation may do.
The enum VALUES are the wire format — they appear in 403 messages and in the dashboard's gating. Renaming one is a breaking change for the dashboard; adding one is not.
keys:read, keys:write, members:read, members:write, billing:read, billing:pay, usage:read, provider_keys:read, provider_keys:write, limits:read, limits:write, alerts:read, alerts:write, org:read, org:write, teams:read, teams:write self, team, org