Rotate Workspace Key Secret
Rotate the secret on a workspace key/secret pair. The key value is unchanged; only secret is regenerated. Backend SDKs using the old secret must switch to the new value.
Rotation is allowed on every record, including the record where is_default is true.
Authorizations
You can get Service Token from SuprSend dashboard -> Account Settings -> Service Tokens section.
Path Parameters
Workspace slug (e.g. staging, production).
Workspace key identifier (e.g. ws_key_...).
Response
Rotation accepted. The response returns the updated record with a new secret; key is unchanged.
A workspace key/secret pair used to authenticate backend SDKs (Suprsend(workspace_key, workspace_secret)).
Unlike ws_api_key, both key and secret are returned in full plain text on every response - list, detail, create and rotate. Treat every response as sensitive: do not log it, do not surface it to browsers, and store the secret only in an environment variable or secrets manager.
Unique identifier of the workspace key. Format is ws_key_ followed by a 26-character ULID.
"ws_key_01ABCDEFGHJKMNPQRSTVWXYZ0"
Label for the workspace key. Unique across the workspace's ws_key records.
"ops-cli"
Full workspace key value. This is the workspace_key passed to backend SDKs when authenticating (Suprsend(workspace_key, workspace_secret)). Returned in plain text on every response.
Rotation does not change key - only secret is regenerated.
"SS.WSK.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
Full workspace secret. This is the workspace_secret passed to backend SDKs when authenticating (Suprsend(workspace_key, workspace_secret)). Returned in plain text on every response, not masked and not "returned once".
Anyone with read access to this response can authenticate as this workspace. Handle every list, detail, create and rotate response as sensitive data.
"SS.WSS.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
Whether this is the workspace's default key/secret pair. The default record cannot be deleted; it can be rotated.
Whether this workspace key can authenticate requests.
Whether this workspace key has been deleted.
Array of domain strings associated with the workspace key.
Timestamp when the workspace key was created.
Identity that performed an action (created, updated, rolled, deleted, rotated).
Timestamp when the workspace secret was last rotated.
Identity that performed an action (created, updated, rolled, deleted, rotated).
Timestamp when the workspace key was deleted, if applicable.
Identity that performed an action (created, updated, rolled, deleted, rotated).