> ## Documentation Index
> Fetch the complete documentation index at: https://docs.uplint.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update API Key

> Update the name, scopes, status, or metadata of an existing API key.



## OpenAPI

````yaml PATCH /api/v1/api-keys/{api_key_id}
openapi: 3.0.3
info:
  title: Uplint API
  version: 0.1.0
  description: >-
    Uplint is a file safety and integrity platform. Upload files through
    context-aware pipelines that automatically validate integrity, detect blank
    or placeholder content, and scan for viruses — all behind a single API.


    This specification covers the core Uplint REST API:


    - **API Keys** — Create and manage scoped API keys for programmatic access.

    - **File Contexts** — Define upload pipelines with per-context rules
    (allowed extensions, size limits, blank/corrupt rejection, virus scanning,
    rate limits, and storage quotas).

    - **Files** — Upload, list, download, inspect, and delete files. Every
    upload runs through the validation pipeline configured on its context.


    All endpoints are tenant-scoped. Authenticate with an API key or JWT token
    via the `Authorization` header.
  contact:
    name: Uplint Team
    url: https://uplint.dev
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.uplint.dev
    description: Production
  - url: http://localhost:8000
    description: Local development
security:
  - BearerAuth: []
tags:
  - name: API Keys
    description: >-
      Create, list, inspect, update, and revoke API keys. Each key carries
      scoped permissions (`upload`, `download`, `metadata`, `delete`, `admin`)
      and is bound to the authenticated tenant.
  - name: File Contexts
    description: >-
      File contexts define upload pipelines. Each context specifies allowed
      extensions, max file size, whether to reject blank or corrupt files, virus
      scanning, rate limits, and storage quotas. Files are always uploaded into
      a context.
  - name: Files
    description: >-
      Upload, list, download, inspect metadata, and delete files. Every upload
      is validated against its context rules before storage.
  - name: Storage Buckets
    description: >-
      Manage the S3 buckets a tenant stores files in. Each tenant can register
      multiple buckets (bring-your-own S3 credentials); one is the **default**
      (fallback) bucket, and file contexts can be routed to any active bucket.
      All storage endpoints require an `admin`-scoped API key.
paths:
  /api/v1/api-keys/{api_key_id}:
    patch:
      tags:
        - API Keys
      summary: Update API key
      description: Update the name, scopes, status, or metadata of an existing API key.
      operationId: updateApiKey
      parameters:
        - $ref: '#/components/parameters/ApiKeyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateAPIKeyRequest'
            example:
              name: Backend Service v2
              scopes:
                - upload
                - download
                - metadata
                - delete
      responses:
        '200':
          description: API key updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse_APIKeyDetail'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/ValidationError'
components:
  parameters:
    ApiKeyId:
      name: api_key_id
      in: path
      required: true
      schema:
        type: string
      description: The API key's unique identifier.
  schemas:
    UpdateAPIKeyRequest:
      type: object
      properties:
        name:
          type: string
          minLength: 1
          maxLength: 255
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/APIKeyScope'
        status:
          $ref: '#/components/schemas/APIKeyStatus'
        metadata:
          type: object
          additionalProperties: true
          nullable: true
    SuccessResponse_APIKeyDetail:
      type: object
      properties:
        status:
          type: string
          enum:
            - SUCCESS
        message:
          type: string
        data:
          $ref: '#/components/schemas/APIKeyDetailResponse'
        timestamp:
          type: string
          format: date-time
    APIKeyScope:
      type: string
      enum:
        - upload
        - download
        - metadata
        - delete
        - admin
      description: Permission scope for an API key. `admin` grants all permissions.
    APIKeyStatus:
      type: string
      enum:
        - active
        - disabled
        - revoked
    APIKeyDetailResponse:
      type: object
      properties:
        api_key_id:
          type: string
        tenant_id:
          type: string
        name:
          type: string
        key_prefix:
          type: string
          description: First characters of the key for identification.
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/APIKeyScope'
        status:
          $ref: '#/components/schemas/APIKeyStatus'
        expires_at:
          type: string
          format: date-time
          nullable: true
        last_used_at:
          type: string
          format: date-time
          nullable: true
        metadata:
          type: object
          additionalProperties: true
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      properties:
        status:
          type: string
          enum:
            - ERROR
        message:
          type: string
        errors:
          type: array
          items:
            type: string
        timestamp:
          type: string
          format: date-time
  responses:
    Unauthorized:
      description: Missing, invalid, or expired authentication credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Invalid or missing API key
            errors:
              - Authentication required
            timestamp: '2026-02-10T12:00:00Z'
    NotFound:
      description: The requested resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Resource not found
            errors:
              - Not found
            timestamp: '2026-02-10T12:00:00Z'
    ValidationError:
      description: Request body failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Validation error
            errors:
              - 'name: field required'
            timestamp: '2026-02-10T12:00:00Z'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Pass an API key or JWT token. API keys can be sent as `Authorization:
        Bearer <key>` or `Authorization: <key>`.

````