Rotate a service-account token

POST /api/v1/public/tokens/{tokenId}/rotate

POST /api/v1/public/tokens/{tokenId}/rotate

Create or trigger tokens rotate.

Operation ID: post_api_v1_public_tokens_tokenId_rotate.

Authentication

Choose a credential. Each row is an accepted alternative; access also depends on current roles, project bindings, and entitlements.

CredentialCarrierOAuth scopes
OAuth2Authorization: Beareraccess:write

Availability

This operation requires the service-account-token-mint capability to be enabled for the deployment. Its presence in the contract does not guarantee availability. See operation availability.

Request parameters

NameLocationRequiredType / allowed valuesDescription / constraints
tokenIdpathYesstringtokenId path parameter; format: uuid; Pattern constrained; see the downloadable schema.
idempotency-keyheaderYesstringidempotency-key header parameter; Required canonical UUIDv4 or high-entropy base64url idempotency key; minLength: 22; maxLength: 43; Pattern constrained; see the downloadable schema.
x-neatlogs-secret-replay-keyheaderYesany & anyx-neatlogs-secret-replay-key header parameter; Required 32-byte unpadded base64url secret replay key; minLength: 43; maxLength: 43

Request body

Body required: yes.

application/json

FieldType / allowed valuesRequired in parentDescription / constraints
$objectYesadditionalProperties: false
expiresInDaysintegerNodefault: 90; minimum: 1; maximum: 365
namestringYesminLength: 1; maxLength: 255; Pattern constrained; see the downloadable schema.
scopesarray<"context:read" | "project:write" | "observability:read" | "observability:write" | "evaluation:read" | "evaluation:write" | "configuration:read" | "configuration:write" | "sharing:read" | "sharing:write" | "access:read" | "access:write">YesminItems: 1; uniqueItems: true
scopes[]"context:read" | "project:write" | "observability:read" | "observability:write" | "evaluation:read" | "evaluation:write" | "configuration:read" | "configuration:write" | "sharing:read" | "sharing:write" | "access:read" | "access:write"Yes—

Request example

Replace placeholder IDs and environment variables with values from your authorized project. Credentials are expanded into curl's stdin configuration, not its command arguments. Keep shell tracing off and do not log this configuration. For requests with a body, put a payload matching the schema in request-body.txt; form requests use URL-encoded content.

curl --fail-with-body --silent --show-error --config - <<CURL_CONFIG
request = "POST"
header = "Authorization: Bearer ${NEATLOGS_TOKEN}"
header = "idempotency-key: ${IDEMPOTENCY_KEY}"
header = "x-neatlogs-secret-replay-key: ${X_NEATLOGS_SECRET_REPLAY_KEY}"
header = "Content-Type: application/json"
data-binary = "@request-body.txt"
url = "https://app.neatlogs.com/api/v1/public/tokens/<tokenId>/rotate"
CURL_CONFIG

Responses

StatusDescriptionContent type
201Service-account token rotatedapplication/json
400Invalid public API requestapplication/problem+json
401Missing or invalid public API credentialapplication/problem+json
403Public API request is not authorizedapplication/problem+json
404Public API resource not foundapplication/problem+json
409Public API rotation conflictapplication/problem+json
413Public API request body too largeapplication/problem+json
415Unsupported public API request bodyapplication/problem+json
429Public API rate limit exceededapplication/problem+json
500Internal server errorapplication/problem+json
503Public API credential, project context, or rate limiting unavailable. Backend is draining; retry after the Retry-After delay.application/problem+json, application/json

201 response fields

Content type: application/json.

FieldType / allowed valuesRequired in parentDescription / constraints
$objectYesadditionalProperties: false
dataobjectYesadditionalProperties: false
data.aadobjectYesadditionalProperties: false
data.aad.actorIdstringYesformat: uuid; Pattern constrained; see the downloadable schema.
data.aad.actorKind"user"Yes—
data.aad.environmentstringYesPattern constrained; see the downloadable schema.
data.aad.idempotencyKeyDigeststringYesPattern constrained; see the downloadable schema.
data.aad.operationId"post_api_v1_public_tokens_tokenId_rotate"Yes—
data.aad.orgIdstringYesformat: uuid; Pattern constrained; see the downloadable schema.
data.aad.projectIdnullYes—
data.aad.recordIdstringYesformat: uuid; Pattern constrained; see the downloadable schema.
data.aad.requestFingerprintobjectYesadditionalProperties: false
data.aad.requestFingerprint.digeststringYesPattern constrained; see the downloadable schema.
data.aad.requestFingerprint.keyIdstringYesPattern constrained; see the downloadable schema.
data.aad.requestFingerprint.version1Yes—
data.aad.responseobjectYesadditionalProperties: false
data.aad.response.contentType"application/json"Yes—
data.aad.response.schemaVersion1Yes—
data.aad.response.status201Yes—
data.aad.version1Yes—
data.algorithm"A256GCM"Yes—
data.authTagstringYesminLength: 22; maxLength: 22; Pattern constrained; see the downloadable schema.
data.ciphertextstringYesminLength: 1; maxLength: 21846; Pattern constrained; see the downloadable schema.
data.kind"client_wrapped_secret"Yes—
data.noncestringYesminLength: 16; maxLength: 16; Pattern constrained; see the downloadable schema.
data.version1Yes—
requestIdstringYesPattern constrained; see the downloadable schema.
successtrueYes—

Response headers

HeaderDescription / constraints
RateLimit-LimitEffective request ceiling for the current window; minimum: 1
RateLimit-RemainingRequests remaining in the current window; minimum: 0
RateLimit-ResetUnix timestamp in seconds when the current window resets; minimum: 0
X-NeatLogs-RateLimit-DegradedWhether bounded emergency enforcement is active; —
X-NeatLogs-RateLimit-LimitEffective request ceiling for the current window; minimum: 1
X-NeatLogs-RateLimit-PolicyApplied pre-authentication or authenticated rate class; —
X-NeatLogs-RateLimit-RemainingRequests remaining in the current window; minimum: 0
X-NeatLogs-RateLimit-Reset-AfterWhole seconds until the current window resets; minimum: 1
X-NeatLogs-RateLimit-VersionNeatLogs rate-limit contract version; —
X-Request-IdServer-owned request correlation identifier; Pattern constrained; see the downloadable schema.

Failures use Problem Details. For exact validation patterns and all response schemas, download the OpenAPI specification.

On this page

Ask Neatlogs AI

Answers from the docs

How can I help?

Ask anything about instrumenting, tracing, or the Neatlogs dashboard.