API / delete-an-xai-api-key-via-management-api

API

Delete an xAI API key via the Management API

Permanently remove an inference API key over HTTP when a leaked secret, finished temporary key, or offboarding checklist requires the key to stop authenticating with no undo. Official Accounts and Authorization documents DELETE /auth/api-keys/{apiKeyId} on https://management-api.x.ai, authorized with a management key, and marks the operation as permanently irrevocable. The Management API guide shows the same DELETE with the management Bearer. Create the management key first with Create a management key in the xAI Console if you do not already have one.

What you need

A management key that can delete API keys for the team, the target apiKeyId from create or List API keys via the xAI Management API (never the secret string in the path), and confirmation that no production client still depends on that key. When you only need to stop traffic temporarily, prefer disabling via Update an xAI API key via the Management API with disabled and a matching fieldMask instead of delete. Neighboring key jobs also include Rotate an xAI API key via the Management API and Create an xAI API key via the Management API. More API jobs live on the API hub.

Delete the key

  1. Export the management key and API key id outside of source control, and confirm the id against a fresh list so you do not delete a sibling key:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_API_KEY_ID="your_api_key_id"
  1. Delete the API key with the documented DELETE route:
curl "https://management-api.x.ai/auth/api-keys/${XAI_API_KEY_ID}" \
  -X DELETE \
  -H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
  1. Expect an empty JSON object on success per the docs example, then re-list the team keys and confirm the apiKeyId is gone. Remove the secret from every vault, CI variable, and local env that still holds it, because delete does not rotate a replacement—clients that still send the old Bearer will fail until you mint a new key with Create an xAI API key via the Management API.

  2. Choose delete only when the key must never authenticate again. For a grace period while you cut over clients, use Rotate an xAI API key via the Management API so the old secret can expire on a controlled schedule, or disable the key with update until the cutover finishes.

Keep every call on https://management-api.x.ai, because an inference API key against https://api.x.ai will not delete Management-managed keys.

Close the loop after delete

Record the delete in your change ticket with the apiKeyId and timestamp, then verify related audit events with List audit events via the xAI Management API. Pair with Manage API keys with the xAI Management API when list, create, update, and rotate sit beside this single delete job in the same runbook.

Pitfalls

Putting the secret string in the path instead of apiKeyId fails or targets the wrong resource. Deleting when you meant disable removes the only recovery path short of creating a new key. Skipping the post-delete vault scrub leaves dead secrets in CI that confuse the next incident. Calling DELETE against https://api.x.ai with an inference Bearer never hits this Management route.