Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
Replace a key with a new one. The new key copies the old one’s identity, permissions, roles, credits, rate limits, metadata, name, enabled state, and expiry. The expiry is the same date, so a key close to expiry gets a replacement close to expiry too. Use update-key to set a new one. The response has the new key’s plaintext, and you only see it once, so save it. The old key expires after --expiration milliseconds so callers have time to switch. It can keep verifying for about 10 seconds past that. Calls POST /v2/keys.rerollKey. See Rerolling keys.

Usage

Flags

integer
required
Milliseconds until the old key expires. The expiry is rounded up to the next whole minute, so the old key can work up to a minute longer than you asked. 0 expires it right away. The old key isn’t deleted. After it expires, it verifies with valid: false and code EXPIRED.
string
required
Id of the key to reroll.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

api.*.create_key or api.<apiId>.create_key, plus api.*.encrypt_key or api.<apiId>.encrypt_key when the original key is recoverable. See Root key permissions.

Examples

Reroll with a one day overlap
Reroll and revoke immediately
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026