Skip to content

Update MCP API Key

Method

REST method is adopted.

HTTP Method

PUT: Update MCP API key information

Naming Convention

To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.

Request and Response

Headers

Meta information is set in HTTP headers, not in the response body.

Request Headers

  • Authorization
  • Content-Type
  • Accept
  • Accept-language

Response Headers

  • Content-Type

Update MCP API Key

URI

PUT /v1/organizations/{organization_id}/projects/{project_id}/mcp_api_key/{mcp_api_key_id}

Path Parameters

Name Type Required Description
organization_id integer Required Organization ID
project_id integer Required Project ID
mcp_api_key_id integer Required MCP API key ID

Request Body

The request body is JSON.

{
  "name": "Updated API Key Name",
  "permission": 1,
  "expiresAt": 1735689600000
}

Request Parameters

Name Type Required Description
name string Optional API key name (max 255 characters)
permission integer Optional Access permission (0: READ, 1: WRITE)
expiresAt integer Optional Expiry timestamp (epoch milliseconds, null means unlimited)

Response

The response is JSON.

{
  "id": 1,
  "userId": 1,
  "projectId": 2,
  "name": "Updated API Key Name",
  "keyPrefix": "abc123",
  "permission": 1,
  "expiresAt": 1735689600000,
  "revokedAt": null,
  "lastUsedAt": 1234567890000,
  "createdAt": 1234567890000,
  "updatedAt": 1234567899999,
  "deletedAt": null,
  "createdBy": "user-cognito-sub",
  "updatedBy": "updater-cognito-sub",
  "deletedBy": null
}

Authentication

Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito.

Error Handling

The status codes for error handling are as follows.

Description Status Code Status Name
Invalid request (empty name, name too long, etc.) 400 Bad Request
Missing credentials 401 Unauthorized
Insufficient permissions 403 Forbidden
MCP API key not found 404 Not Found
Internal server error 500 Internal Server Error

Processing Flow

  1. Extract organization ID, project ID, and MCP API key ID from path parameters
  2. Extract update parameters from request body
  3. Verify the user has access to the project
  4. Verify the key exists and has not been deleted
  5. Verify the key is associated with the specified project
  6. Verify the user has permission to update the key
  7. Update the key in the database
  8. Set the updated timestamp and updater
  9. Return the formatted updated key information

Constraints

  • Revoked keys (revokedAt is not null) cannot be updated
  • Deleted keys (deletedAt is not null) cannot be updated
  • userId, projectId, keyPrefix, and scope cannot be updated

Detailed Flowchart

flowchart TD
    Start([PUT Request]) --> Auth[Auth & Parameter Extraction]
    Auth --> Service[Service Layer]
    Service --> AccessCheck[Access Check]
    AccessCheck --> HasAccess{Write permission?}
    HasAccess -->|No| Err404[404 Not Found]
    HasAccess -->|Yes| CheckExist[Check Existence]
    CheckExist --> Exists{Exists?}
    Exists -->|No| Err404
    Exists -->|Yes| CheckOwner{Owner Verification}
    CheckOwner -->|NG| Err404
    CheckOwner -->|OK| UpdateDB[DB Update]
    UpdateDB --> Success[200 OK]