Rotate API key
curl --request POST \
--url https://api.nixflex.com/v1/keys/rotateimport requests
url = "https://api.nixflex.com/v1/keys/rotate"
response = requests.post(url)
print(response.text)const options = {method: 'POST'};
fetch('https://api.nixflex.com/v1/keys/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nixflex.com/v1/keys/rotate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.nixflex.com/v1/keys/rotate"
req, _ := http.NewRequest("POST", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nixflex.com/v1/keys/rotate")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nixflex.com/v1/keys/rotate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
response = http.request(request)
puts response.read_bodyAccount
Rotate API key
POST /v1/keys/rotate
POST
/
v1
/
keys
/
rotate
Rotate API key
curl --request POST \
--url https://api.nixflex.com/v1/keys/rotateimport requests
url = "https://api.nixflex.com/v1/keys/rotate"
response = requests.post(url)
print(response.text)const options = {method: 'POST'};
fetch('https://api.nixflex.com/v1/keys/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nixflex.com/v1/keys/rotate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.nixflex.com/v1/keys/rotate"
req, _ := http.NewRequest("POST", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nixflex.com/v1/keys/rotate")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nixflex.com/v1/keys/rotate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
response = http.request(request)
puts response.read_bodyRotates the
key_secret of your API key. The key_id stays the same — only the secret changes. The old secret stops working immediately.
This is the same model used by Stripe and other major APIs. Your
key_id acts as a stable account identifier across logs and integrations; only the secret material rotates. Most developers rotate via the dashboard.Request
Authenticate with your current key. The endpoint returns a new secret paired with the samekey_id.
curl -X POST https://api.nixflex.com/v1/keys/rotate \
-H "Authorization: Bearer nxf_a1b2c3...:nxfs_x1y2z3..."
Body parameters
None. The endpoint identifies the key from theAuthorization header.
Response
200 OK:
{
"message": "API key secret rotated. Save your new key_secret - it will not be shown again. Update your applications immediately.",
"key_id": "nxf_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6",
"key_secret": "nxfs_NEW_SECRET..."
}
Important
The old
key_secret stops working the instant this endpoint returns. Any application still using the old secret will receive 401 Invalid or missing API key. Update every deployed app, environment variable, and CI/CD secret before rotating in production.The new
key_secret is shown once. If you lose it, you must rotate again.- Copy it immediately into your secrets manager
- Never commit it to source control
- Never include it in client-side JavaScript
When to rotate
- A secret was leaked (committed to a public repo, shared in a chat, etc.)
- Routine security hygiene (every 90 days is a common cadence)
- An employee with access leaves your team
What stays the same
Because only the secret changes, these are not affected by rotation:- Existing calls, agents, phone numbers, SMS messages, batch jobs, campaigns
- Webhook configurations
- Billing and usage history
key_iditself (still appears in logs, dashboard, and API responses)