Update an organization API key's expiry. Requires a user credential (an Owner or Admin of the organization, selected with an Organization-Id). A PORTFOLIO-scope Api-Key caller still must select a target (403 without one, matching every other verb on this family) but is always refused once it has (404), since client-scoped keys have no update capability for any caller. Only a direct organization key can be updated; any other key returns 404. Send expiresAt to set a new expiry or null to remove it; an empty body returns 400. The response is empty on success.
Release date, as YYYY-MM-DD. Defaults to 2026-07-21.
Target organization id (Organization-Id selector). Omit to manage portfolio keys as a bearer. Required for a PORTFOLIO-scope Api-Key, which may only manage one client org's keys at a time.
Target connection id; resolves to its organization.
Platform entity id; resolves to a connection's organization.
Optional source to disambiguate an Entity-Id.
Opaque identifier of the API key to update. Treat as opaque.
New expiry for the key (RFC-3339 UTC with an explicit Z), which must be in the future. Send null to remove the expiry so the key never expires. Omit the field and the request is rejected, since there is nothing to change.
Successful Response
The request was invalid.
Authentication failed or was missing.
The credential is not permitted for this request.
The requested resource was not found.
The request conflicts with existing state.
The request failed validation.
A service this request depends on was unavailable. Retry the request.