developers.key.update
curl --request POST \
--url https://platform.trylath.com/developers/key/update \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"keyId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"permissions": []
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
keyId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
name: '<string>',
permissions: []
})
};
fetch('https://platform.trylath.com/developers/key/update', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://platform.trylath.com/developers/key/update"
payload = {
"keyId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"permissions": []
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.trylath.com/developers/key/update"
payload := strings.NewReader("{\n \"keyId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"name\": \"<string>\",\n \"permissions\": []\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"activityId": "<string>",
"result": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"prefix": "<string>",
"permissions": [
"<string>"
]
}
}developers.key.update
Renames a key or changes the permissions it carries, in place. The key itself is untouched, so nothing has to be redeployed and no request fails while it happens. The new permissions take effect on the next request. A publishable key’s one permission cannot be changed, permissions can only be set to what this caller itself holds, and the last key with developers:write cannot have it taken away.
POST
/
developers
/
key
/
update
developers.key.update
curl --request POST \
--url https://platform.trylath.com/developers/key/update \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"keyId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"permissions": []
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
keyId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
name: '<string>',
permissions: []
})
};
fetch('https://platform.trylath.com/developers/key/update', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://platform.trylath.com/developers/key/update"
payload = {
"keyId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"permissions": []
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.trylath.com/developers/key/update"
payload := strings.NewReader("{\n \"keyId\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"name\": \"<string>\",\n \"permissions\": []\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"activityId": "<string>",
"result": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"prefix": "<string>",
"permissions": [
"<string>"
]
}
}Authorizations
A Lath API key: lath_live_sk… or lath_test_sk… on a server, lath_live_pk… or lath_test_pk… in a browser.
Headers
Replays the stored response for the same key and input; refuses different input.
Body
application/json
Pattern:
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Required string length:
1 - 60Replaces the key's permissions outright; not allowed on a publishable key
Minimum array length:
1Available options:
account:read, account:write, auth:read, auth:write, email:read, email:write, sms:read, sms:write, audience:read, audience:write, developers:read, developers:write, billing:read, billing:write Last modified on September 13, 2026
Was this page helpful?

