Skip to main content
PATCH
Rotate Workspace Key Secret

Authorizations

ServiceToken <token>
string
header
required

You can get Service Token from SuprSend dashboard -> Account Settings -> Service Tokens section.

Path Parameters

workspace
string
required

Workspace slug (e.g. staging, production).

workspace_key_id
string
required

Workspace key identifier (e.g. ws_key_...).

Response

Rotation accepted. The response returns the updated record with a new secret; key is unchanged.

A workspace key/secret pair used to authenticate backend SDKs (Suprsend(workspace_key, workspace_secret)).

Unlike ws_api_key, both key and secret are returned in full plain text on every response - list, detail, create and rotate. Treat every response as sensitive: do not log it, do not surface it to browsers, and store the secret only in an environment variable or secrets manager.

id
string

Unique identifier of the workspace key. Format is ws_key_ followed by a 26-character ULID.

Example:

"ws_key_01ABCDEFGHJKMNPQRSTVWXYZ0"

name
string

Label for the workspace key. Unique across the workspace's ws_key records.

Example:

"ops-cli"

key
string

Full workspace key value. This is the workspace_key passed to backend SDKs when authenticating (Suprsend(workspace_key, workspace_secret)). Returned in plain text on every response.

Rotation does not change key - only secret is regenerated.

Example:

"SS.WSK.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"

secret
string

Full workspace secret. This is the workspace_secret passed to backend SDKs when authenticating (Suprsend(workspace_key, workspace_secret)). Returned in plain text on every response, not masked and not "returned once".

Anyone with read access to this response can authenticate as this workspace. Handle every list, detail, create and rotate response as sensitive data.

Example:

"SS.WSS.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"

is_default
boolean

Whether this is the workspace's default key/secret pair. The default record cannot be deleted; it can be rotated.

is_active
boolean

Whether this workspace key can authenticate requests.

is_deleted
boolean

Whether this workspace key has been deleted.

allowed_domains
string[]

Array of domain strings associated with the workspace key.

created_at
string<date-time>

Timestamp when the workspace key was created.

created_by
object | null

Identity that performed an action (created, updated, rolled, deleted, rotated).

rotated_at
string<date-time> | null

Timestamp when the workspace secret was last rotated.

rotated_by
object | null

Identity that performed an action (created, updated, rolled, deleted, rotated).

deleted_at
string<date-time> | null

Timestamp when the workspace key was deleted, if applicable.

deleted_by
object | null

Identity that performed an action (created, updated, rolled, deleted, rotated).