Regenerate Key
POST/auth/regenerate-key
Regenerate the user's API key, after asking for the password again.
The password is required even inside an active session (ASVS 5.0 7.5.1,
7.5.3): a stolen access token alone cannot replace the key. A wrong one is
401 invalid_credentials; the check spends the per-email login budget.
Atomically revokes the old key and creates a new one. Returns the new raw key ONCE - it will never be retrievable again. Does not reset the daily usage counter: the quota bucket is keyed on the user, not on this key row.
⚠ That is now true. It was not when this line was first written - the
Valkey buckets were keyed on api_keys.id, this endpoint INSERTs a row
with a new id, and every counter therefore read zero afterwards. The
sentence described the slowapi limiter, which is genuinely user-keyed, and
was false of the buckets carrying the published per-endpoint limits. See
core.rate_limit.quota_identity.
Requires Authorization: Bearer access_token header.
Request
Responses
- 200
- 422
Successful Response
Validation Error