Enable Project Key Agentic
Toggle agentic use ON for a Project Key (the agentic toggle).
Atomic: rotates the API client credential, encrypts the new credential file
blob with KMS, stores it on the PK row, sets agentic_enabled=True.
Idempotent on already-enabled PKs (no double rotation).
Rate limit: 5/min/tenant (each call burns one Frontegg credential rotation).
Returns 429 with Retry-After on bucket exhaustion.
Audit-logged with action=enable / enable_noop, actor email + sub, old/new state, tenant_id, project_key_id, timestamp.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Response
Successful Response
Summary response for listing Project Keys (no secrets).
full, read-only, agent-operator, infra-admin Whether this Project Key is wired up as the auth blob behind the Streamkap MCP. Toggled via POST /project-keys/{id}/enable-agentic and disable-agentic. When true, the encrypted credential lives on the PK row (server-side only); the agent picker on the FE filters to PKs where this is true.
Always masked to '********' on responses when agentic_enabled is true; null otherwise. Server-derived only - PUT/PATCH bodies that include this field are rejected with 422.