Skip to content
Streamkap
Esc
↑↓navigate↵open⌘Jpreview

Update Project Key

Update a Project Key’s name, description, roles, tool scoping, or Kafka ACLs.

Supports additive capability transitions:

  • Send kafka_config on an API-only PK to add Kafka access. Response will include new_kafka_credentials with the plaintext Kafka password (shown once).
  • Send role_ids or permission_ids on a Kafka-only PK to add API credentials. Response will include new_api_credentials with the plaintext client_secret (shown once).

Returns 400 if the key is in creating/deleting/delete_failed state. role_ids and permission_ids are mutually exclusive.

PATCH/project-keys/{project_key_id}
Authorization
AuthorizationBearer token · headerrequired
Path parameters
project_key_idstringrequired
Request body
requiredapplication/json
namestring | null

Updated name

Show properties
Any of:
string
string
null
null
descriptionstring | null

Updated description (HTML sanitized)

Show properties
Any of:
string
string
null
null
role_idsstring[] | null

Change the Frontegg roles for this PK, or assign roles when adding API access to a Kafka-only PK. Note: changing roles on an existing API credential only takes effect when the current JWT expires. See token_ttl_seconds in the detail response for the validity window.

Show properties
Any of:
string[]
Array of string
string
null
null
permission_idsstring[] | null

Assign fine-grained permissions when ADDING API access to a Kafka-only PK. Changing permissions on an existing API credential is NOT supported - to change permissions on an existing PK, either switch to role_ids or delete and recreate the PK. This field is only accepted when the PK has no api_client_id yet.

Show properties
Any of:
string[]
Array of string
string
null
null
kafka_aclsKafkaAclModel[] | null
Show properties
Any of:
KafkaAclModel[]
Array of KafkaAclModel
topic_namestringrequired
operationstringrequired
resource_pattern_typestringrequired
resourcestring
default: "TOPIC"
null
null
whitelist_ipsstring | null
Show properties
Any of:
string
string
null
null
kafka_configProjectKeyKafkaConfig | null

Add Kafka access to a PK that currently has none. Only valid when the PK has no Kafka user yet.

Show properties
Any of:
ProjectKeyKafkaConfig
usernamestringrequired

Kafka username (alphanumeric + hyphens, 3-24 chars)

min length 3 · max length 24 · matches ^[a-zA-Z0-9-]+$
passwordstringrequired

Kafka SASL password (12-128 chars)

min length 12 · max length 128
whitelist_ipsstring | null

Comma-separated IP addresses or CIDR ranges

Show properties
Any of:
string
string
null
null
kafka_aclsKafkaAclModel[]

Kafka ACL rules for topic/group access control

Show properties
Array of KafkaAclModel
topic_namestringrequired
operationstringrequired
resource_pattern_typestringrequired
resourcestring
default: "TOPIC"
is_create_schema_registryboolean

Whether to create a Schema Registry proxy

default: false
null
null
kafka_passwordstring | null

Rotate the Kafka SASL password for an existing Kafka user. PK must have kafka_username.

Show properties
Any of:
string
string
null
null
tool_profileToolProfile | null
Show properties
Any of:
ToolProfile
string
null
null
allowed_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
blocked_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
Responses
200

Successful Response

idstringrequired
namestringrequired
descriptionstring | null
Show properties
Any of:
string
string
null
null
created_atstring<date-time> | null
Show properties
Any of:
string<date-time>
string<date-time>
null
null
created_by_userUser | null
Show properties
Any of:
User
idstringrequired
emailstringrequired
namestringrequired
profile_picture_urlstring | null
Show properties
Any of:
string
string
null
null
phone_numberstring | null
Show properties
Any of:
string
string
null
null
tenant_idstringrequired
created_atstring | string<date-time> | null
Show properties
Any of:
string
string
string<date-time>
string<date-time>
null
null
last_loginstring | string<date-time> | null
Show properties
Any of:
string
string
string<date-time>
string<date-time>
null
null
null
null
api_client_idstring | null
Show properties
Any of:
string
string
null
null
api_client_id_masked_secretstring | null
Show properties
Any of:
string
string
null
null
kafka_usernamestring | null
Show properties
Any of:
string
string
null
null
service_idstringrequired
rolesRole[]
Show properties
Array of Role
idstringrequired
keystringrequired
namestringrequired
descriptionstring | nullrequired
Show properties
Any of:
string
string
null
null
created_atstring | string<date-time> | null
Show properties
Any of:
string
string
string<date-time>
string<date-time>
null
null
updated_atstring | string<date-time> | null
Show properties
Any of:
string
string
string<date-time>
string<date-time>
null
null
permissionsstring[]
statusstringrequired
last_used_atstring<date-time> | null
Show properties
Any of:
string<date-time>
string<date-time>
null
null
tool_profileToolProfile | null
Show properties
Any of:
ToolProfile
string
null
null
allowed_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
blocked_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
agentic_enabledboolean

Whether this Project Key is wired up as the auth blob behind the Streamkap MCP. Toggled via POST /project-keys/{id}/enable-agentic and disable-agentic. When true, the encrypted credential lives on the PK row (server-side only); the agent picker on the FE filters to PKs where this is true.

default: false
agentic_secret_blobstring | null

Always masked to '********' on responses when agentic_enabled is true; null otherwise. Server-derived only - PUT/PATCH bodies that include this field are rejected with 422.

Show properties
Any of:
string
string
null
null
new_api_credentialsProjectKeyApiCredentials | null

Present only when API credentials were ADDED to a Kafka-only PK. Contains the plaintext client_secret - shown only once.

Show properties
Any of:
ProjectKeyApiCredentials
client_idstringrequired
client_secretstringrequired
token_endpointstringrequired
api_urlstringrequired
rolesstring[]
null
null
new_kafka_credentialsProjectKeyKafkaCredentials | null

Present only when Kafka access was ADDED to an API-only PK. Contains the plaintext Kafka password - shown only once.

Show properties
Any of:
ProjectKeyKafkaCredentials
usernamestringrequired
passwordstringrequired
bootstrap_serversstringrequired
security_protocolstring
default: "SASL_SSL"
sasl_mechanismstring
default: "PLAIN"
schema_registry_urlstring | null
Show properties
Any of:
string
string
null
null
null
null
token_ttl_secondsinteger

Current Frontegg JWT TTL in seconds (dynamic). Used by the frontend to compute how long role changes take to propagate.

warningsstring[]

Non-blocking informational messages the frontend should surface to the user after the update (e.g. 'role changes take effect within X hours'). Empty list when there is nothing to warn about.

422

Validation Error

detailValidationError[]
Show properties
Array of ValidationError
locstring | integer[]required
Show properties
Array of string | integer
Any of:
string
string
integer
integer
msgstringrequired
typestringrequired
inputany
ctxobject
Request
curl -X PATCH 'https://api.streamkap.com/project-keys/string' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "description": "string",
  "role_ids": [
    "string"
  ],
  "permission_ids": [
    "string"
  ],
  "kafka_acls": [
    {
      "topic_name": "string",
      "operation": "string",
      "resource_pattern_type": "string",
      "resource": "TOPIC"
    }
  ],
  "whitelist_ips": "string",
  "kafka_config": {
    "username": "string",
    "password": "stringstring",
    "whitelist_ips": "string",
    "kafka_acls": [
      {
        "topic_name": "string",
        "operation": "string",
        "resource_pattern_type": "string",
        "resource": "TOPIC"
      }
    ],
    "is_create_schema_registry": false
  },
  "kafka_password": "stringstring",
  "tool_profile": "full",
  "allowed_tools": [
    "string"
  ],
  "blocked_tools": [
    "string"
  ]
}'
Response
{
  "id": "string",
  "name": "string",
  "description": "string",
  "created_at": "2019-08-24T14:15:22Z",
  "created_by_user": {
    "id": "string",
    "email": "string",
    "name": "string",
    "profile_picture_url": "string",
    "phone_number": "string",
    "tenant_id": "string",
    "created_at": "string",
    "last_login": "string"
  },
  "api_client_id": "string",
  "api_client_id_masked_secret": "string",
  "kafka_username": "string",
  "service_id": "string",
  "roles": [
    {
      "id": "string",
      "key": "string",
      "name": "string",
      "description": "string",
      "created_at": "string",
      "updated_at": "string",
      "permissions": [
        "string"
      ]
    }
  ],
  "status": "string",
  "last_used_at": "2019-08-24T14:15:22Z",
  "tool_profile": "full",
  "allowed_tools": [
    "string"
  ],
  "blocked_tools": [
    "string"
  ],
  "agentic_enabled": false,
  "agentic_secret_blob": "string",
  "new_api_credentials": {
    "client_id": "string",
    "client_secret": "string",
    "token_endpoint": "string",
    "api_url": "string",
    "roles": [
      "string"
    ]
  },
  "new_kafka_credentials": {
    "username": "string",
    "password": "string",
    "bootstrap_servers": "string",
    "security_protocol": "SASL_SSL",
    "sasl_mechanism": "PLAIN",
    "schema_registry_url": "string"
  },
  "token_ttl_seconds": 0,
  "warnings": [
    "string"
  ]
}