Skip to main content
POST
Call keys.rotate

Authorizations

Authorization
string
header
required

An API key minted at Settings › API & MCP. Send it as Authorization: Bearer <key>. A key carries its holder's own permissions, resolved on every call — revoking a membership closes the key's reach immediately. Keep it in an environment variable (GOOSY_API_KEY), never in a committed file.

Headers

x-request-id
string

Your own id for this request, echoed back and recorded on the audit trail. 1–128 characters from A–Z a–z 0–9 . _ : -, starting with a letter or digit; anything else is replaced by a generated id.

Maximum string length: 128

Body

application/json
overlap_hours
integer

How many hours the current key keeps working after the new one exists, 0 to 168. Default 24.

Required range: 0 <= x <= 168
confirmation_id
string<uuid>

Response

The call was admitted and dispatched. ok says whether the tool succeeded — a refusal the tool itself produced is still a 200, exactly as it is a successful JSON-RPC result over MCP.

The tool ran and answered.

ok
boolean
required
state
enum<string>
required
Available options:
confirmation_required,
rotated
overlap_hours
integer
required
previous_key_prefix
string
required
confirmation_id
string<uuid>
expires_in_seconds
integer
key
string
key_prefix
string
key_expires_at
string | null
previous_key_expires_at
string