Update Project Key
Update a Project Key’s name, description, roles, tool scoping, or Kafka ACLs.
Supports additive capability transitions:
- Send
kafka_configon an API-only PK to add Kafka access. Response will includenew_kafka_credentialswith the plaintext Kafka password (shown once). - Send
role_idsorpermission_idson a Kafka-only PK to add API credentials. Response will includenew_api_credentialswith the plaintext client_secret (shown once).
Returns 400 if the key is in creating/deleting/delete_failed state. role_ids and permission_ids are mutually exclusive.
/project-keys/{project_key_id}AuthorizationBearer token · headerrequiredproject_key_idstringrequiredapplication/jsonnamestring | nullUpdated name
Show propertiesHide properties
stringnulldescriptionstring | nullUpdated description (HTML sanitized)
Show propertiesHide properties
stringnullrole_idsstring[] | nullChange the Frontegg roles for this PK, or assign roles when adding API access to a Kafka-only PK. Note: changing roles on an existing API credential only takes effect when the current JWT expires. See token_ttl_seconds in the detail response for the validity window.
Show propertiesHide properties
stringstringnullpermission_idsstring[] | nullAssign fine-grained permissions when ADDING API access to a Kafka-only PK. Changing permissions on an existing API credential is NOT supported - to change permissions on an existing PK, either switch to role_ids or delete and recreate the PK. This field is only accepted when the PK has no api_client_id yet.
Show propertiesHide properties
stringstringnullkafka_aclsKafkaAclModel[] | nullShow propertiesHide properties
KafkaAclModeltopic_namestringrequiredoperationstringrequiredresource_pattern_typestringrequiredresourcestringnullwhitelist_ipsstring | nullShow propertiesHide properties
stringnullkafka_configProjectKeyKafkaConfig | nullAdd Kafka access to a PK that currently has none. Only valid when the PK has no Kafka user yet.
Show propertiesHide properties
usernamestringrequiredKafka username (alphanumeric + hyphens, 3-24 chars)
passwordstringrequiredKafka SASL password (12-128 chars)
whitelist_ipsstring | nullComma-separated IP addresses or CIDR ranges
Show propertiesHide properties
stringnullkafka_aclsKafkaAclModel[]Kafka ACL rules for topic/group access control
Show propertiesHide properties
KafkaAclModeltopic_namestringrequiredoperationstringrequiredresource_pattern_typestringrequiredresourcestringis_create_schema_registrybooleanWhether to create a Schema Registry proxy
nullkafka_passwordstring | nullRotate the Kafka SASL password for an existing Kafka user. PK must have kafka_username.
Show propertiesHide properties
stringnulltool_profileToolProfile | nullShow propertiesHide properties
stringnullallowed_toolsstring[] | nullShow propertiesHide properties
stringstringnullblocked_toolsstring[] | nullShow propertiesHide properties
stringstringnullSuccessful Response
idstringrequirednamestringrequireddescriptionstring | nullShow propertiesHide properties
stringnullcreated_atstring<date-time> | nullShow propertiesHide properties
string<date-time>nullcreated_by_userUser | nullShow propertiesHide properties
idstringrequiredemailstringrequirednamestringrequiredprofile_picture_urlstring | nullShow propertiesHide properties
stringnullphone_numberstring | nullShow propertiesHide properties
stringnulltenant_idstringrequiredcreated_atstring | string<date-time> | nullShow propertiesHide properties
stringstring<date-time>nulllast_loginstring | string<date-time> | nullShow propertiesHide properties
stringstring<date-time>nullnullapi_client_idstring | nullShow propertiesHide properties
stringnullapi_client_id_masked_secretstring | nullShow propertiesHide properties
stringnullkafka_usernamestring | nullShow propertiesHide properties
stringnullservice_idstringrequiredrolesRole[]Show propertiesHide properties
Roleidstringrequiredkeystringrequirednamestringrequireddescriptionstring | nullrequiredShow propertiesHide properties
stringnullcreated_atstring | string<date-time> | nullShow propertiesHide properties
stringstring<date-time>nullupdated_atstring | string<date-time> | nullShow propertiesHide properties
stringstring<date-time>nullpermissionsstring[]statusstringrequiredlast_used_atstring<date-time> | nullShow propertiesHide properties
string<date-time>nulltool_profileToolProfile | nullShow propertiesHide properties
stringnullallowed_toolsstring[] | nullShow propertiesHide properties
stringstringnullblocked_toolsstring[] | nullShow propertiesHide properties
stringstringnullagentic_enabledbooleanWhether this Project Key is wired up as the auth blob behind the Streamkap MCP. Toggled via POST /project-keys/{id}/enable-agentic and disable-agentic. When true, the encrypted credential lives on the PK row (server-side only); the agent picker on the FE filters to PKs where this is true.
agentic_secret_blobstring | nullAlways masked to '********' on responses when agentic_enabled is true; null otherwise. Server-derived only - PUT/PATCH bodies that include this field are rejected with 422.
Show propertiesHide properties
stringnullnew_api_credentialsProjectKeyApiCredentials | nullPresent only when API credentials were ADDED to a Kafka-only PK. Contains the plaintext client_secret - shown only once.
Show propertiesHide properties
client_idstringrequiredclient_secretstringrequiredtoken_endpointstringrequiredapi_urlstringrequiredrolesstring[]nullnew_kafka_credentialsProjectKeyKafkaCredentials | nullPresent only when Kafka access was ADDED to an API-only PK. Contains the plaintext Kafka password - shown only once.
Show propertiesHide properties
usernamestringrequiredpasswordstringrequiredbootstrap_serversstringrequiredsecurity_protocolstringsasl_mechanismstringschema_registry_urlstring | nullShow propertiesHide properties
stringnullnulltoken_ttl_secondsintegerCurrent Frontegg JWT TTL in seconds (dynamic). Used by the frontend to compute how long role changes take to propagate.
warningsstring[]Non-blocking informational messages the frontend should surface to the user after the update (e.g. 'role changes take effect within X hours'). Empty list when there is nothing to warn about.
Validation Error
detailValidationError[]Show propertiesHide properties
ValidationErrorlocstring | integer[]requiredShow propertiesHide properties
string | integerstringintegermsgstringrequiredtypestringrequiredinputanyctxobject