Roll website key
PUT https://datafa.st/api/v1/admin/websites/{websiteId}/apikeys/{apiKeyId}Regenerate a
df_ website API key, invalidating the old value. The new full key is returned once.Use this to rotate compromised keys without creating a new key record.
Request
Path parameters
websiteIdstring
apiKeyIdstring
Website API key ObjectId from List website keys.
Response
Returns a JSON object with
status: "success" and endpoint-specific fields in data.Response fields
data[].idstring
Website API key ObjectId.
data[].userIdstring
User ObjectId that owns the key.
data[].namestring|null
Human-readable name for the resource or event. The exact meaning depends on the endpoint.
data[].displayKeystring
Masked key shown in the dashboard.
data[].websiteIdstring
Website ObjectId used by account tokens to choose which website to query or manage.
data[].keyPrefixstring
Indexed key prefix used for lookup.
data[].lastUsedAtstring|null
Last usage timestamp.
data[].usageCountnumber
Number of authenticated uses.
data[].isMobileboolean
Whether the key was created for the mobile app. Mobile keys are excluded from list responses.
data[].createdAtstring
Creation timestamp.
data[].updatedAtstring
Last update timestamp.
data[].keystring
Only returned when creating or rolling a key. Full raw key shown once.
Authentication
Use a
dft_ account token with api-keys:write.A
df_ website API key for the same website can also call this route when the path websiteId matches the key's website. Write access with a df_ key is capped at member level — owner-only actions such as team management require a dft_ token and owner role.Errors
See API errors for the standard error envelope, auth failures, validation errors, permission errors, and rate limits.