Update MCP API Key
Method
REST method is adopted.
HTTP Method
PUT: Update MCP API key information
Naming Convention
To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.
Request and Response
Headers
Meta information is set in HTTP headers, not in the response body.
Request Headers
AuthorizationContent-TypeAcceptAccept-language
Response Headers
Content-Type
Update MCP API Key
URI
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| organization_id | integer | Required | Organization ID |
| project_id | integer | Required | Project ID |
| mcp_api_key_id | integer | Required | MCP API key ID |
Request Body
The request body is JSON.
Request Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| name | string | Optional | API key name (max 255 characters) |
| permission | integer | Optional | Access permission (0: READ, 1: WRITE) |
| expiresAt | integer | Optional | Expiry timestamp (epoch milliseconds, null means unlimited) |
Response
The response is JSON.
{
"id": 1,
"userId": 1,
"projectId": 2,
"name": "Updated API Key Name",
"keyPrefix": "abc123",
"permission": 1,
"expiresAt": 1735689600000,
"revokedAt": null,
"lastUsedAt": 1234567890000,
"createdAt": 1234567890000,
"updatedAt": 1234567899999,
"deletedAt": null,
"createdBy": "user-cognito-sub",
"updatedBy": "updater-cognito-sub",
"deletedBy": null
}
Authentication
Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito.
Error Handling
The status codes for error handling are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| Invalid request (empty name, name too long, etc.) | 400 | Bad Request |
| Missing credentials | 401 | Unauthorized |
| Insufficient permissions | 403 | Forbidden |
| MCP API key not found | 404 | Not Found |
| Internal server error | 500 | Internal Server Error |
Processing Flow
- Extract organization ID, project ID, and MCP API key ID from path parameters
- Extract update parameters from request body
- Verify the user has access to the project
- Verify the key exists and has not been deleted
- Verify the key is associated with the specified project
- Verify the user has permission to update the key
- Update the key in the database
- Set the updated timestamp and updater
- Return the formatted updated key information
Constraints
- Revoked keys (
revokedAtis not null) cannot be updated - Deleted keys (
deletedAtis not null) cannot be updated userId,projectId,keyPrefix, andscopecannot be updated
Detailed Flowchart
flowchart TD
Start([PUT Request]) --> Auth[Auth & Parameter Extraction]
Auth --> Service[Service Layer]
Service --> AccessCheck[Access Check]
AccessCheck --> HasAccess{Write permission?}
HasAccess -->|No| Err404[404 Not Found]
HasAccess -->|Yes| CheckExist[Check Existence]
CheckExist --> Exists{Exists?}
Exists -->|No| Err404
Exists -->|Yes| CheckOwner{Owner Verification}
CheckOwner -->|NG| Err404
CheckOwner -->|OK| UpdateDB[DB Update]
UpdateDB --> Success[200 OK]