curl --request PATCH \
--url https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"permissions": []
}
'import requests
url = "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}"
payload = { "permissions": [] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({permissions: []})
};
fetch('https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'permissions' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}"
payload := strings.NewReader("{\n \"permissions\": []\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"permissions\": []\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"permissions\": []\n}"
response = http.request(request)
puts response.read_body{
"apiKey": {
"apiKeyId": "<string>",
"createdAt": "2026-01-01T00:00:00.000Z",
"createdByAccountId": "<string>",
"expiresAt": "2026-01-01T00:00:00.000Z",
"name": "<string>",
"permissions": [
"<string>"
],
"permissionsUpdatedAt": "2026-01-01T00:00:00.000Z",
"projectId": "<string>",
"revokedAt": "2026-01-01T00:00:00.000Z"
}
}{
"code": "IDEMPOTENCY_KEY_REQUIRED",
"status": 400,
"title": "Idempotency Key Required",
"type": "https://photon.codes/docs/problems/idempotency-key-required"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "PROJECT_NOT_FOUND",
"status": 404,
"title": "Project Not Found",
"type": "https://photon.codes/docs/problems/project-not-found"
}{
"code": "API_KEY_REVOKED",
"status": 409,
"title": "API Key Revoked",
"type": "https://photon.codes/docs/problems/api-key-revoked"
}{
"code": "PROJECT_DELETED",
"status": 410,
"title": "Project Deleted",
"type": "https://photon.codes/docs/problems/project-deleted"
}{
"code": "PAYLOAD_TOO_LARGE",
"status": 413,
"title": "Payload Too Large",
"type": "https://photon.codes/docs/problems/payload-too-large"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "REQUEST_TIMEOUT",
"status": 504,
"title": "Request Timeout",
"type": "https://photon.codes/docs/problems/request-timeout"
}Update project API key permissions
Replaces the identified project key’s permission list with the supplied permissions and returns the updated metadata. Sending the permission list the key already has leaves it unchanged. This request does not create a new secret or change the key’s project binding. Supply the required Idempotency-Key header.
curl --request PATCH \
--url https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"permissions": []
}
'import requests
url = "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}"
payload = { "permissions": [] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({permissions: []})
};
fetch('https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'permissions' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}"
payload := strings.NewReader("{\n \"permissions\": []\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"permissions\": []\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/projects/{projectId}/api-keys/{apiKeyId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"permissions\": []\n}"
response = http.request(request)
puts response.read_body{
"apiKey": {
"apiKeyId": "<string>",
"createdAt": "2026-01-01T00:00:00.000Z",
"createdByAccountId": "<string>",
"expiresAt": "2026-01-01T00:00:00.000Z",
"name": "<string>",
"permissions": [
"<string>"
],
"permissionsUpdatedAt": "2026-01-01T00:00:00.000Z",
"projectId": "<string>",
"revokedAt": "2026-01-01T00:00:00.000Z"
}
}{
"code": "IDEMPOTENCY_KEY_REQUIRED",
"status": 400,
"title": "Idempotency Key Required",
"type": "https://photon.codes/docs/problems/idempotency-key-required"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "PROJECT_NOT_FOUND",
"status": 404,
"title": "Project Not Found",
"type": "https://photon.codes/docs/problems/project-not-found"
}{
"code": "API_KEY_REVOKED",
"status": 409,
"title": "API Key Revoked",
"type": "https://photon.codes/docs/problems/api-key-revoked"
}{
"code": "PROJECT_DELETED",
"status": 410,
"title": "Project Deleted",
"type": "https://photon.codes/docs/problems/project-deleted"
}{
"code": "PAYLOAD_TOO_LARGE",
"status": 413,
"title": "Payload Too Large",
"type": "https://photon.codes/docs/problems/payload-too-large"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "REQUEST_TIMEOUT",
"status": 504,
"title": "Request Timeout",
"type": "https://photon.codes/docs/problems/request-timeout"
}Authorizations
Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.
Headers
Identifies one logical mutation across retries.
1 - 255^[\x21-\x7e]{1,255}$Body
1events:read, events:write, platforms:read, platforms:write, project:read, project:write Response
The key with its new permission list. Sending the list it already holds returns it unchanged.
Show child attributes
Show child attributes
Was this page helpful?