
Update an xAI API key via the Management API
Change selected fields on an existing inference API key over HTTP when you need to raise or lower rate limits, rename the key, disable it, adjust ACL strings, or set an expiration without minting a new secret. Official Accounts and Authorization documents PUT /auth/api-keys/{api_key_id} on https://management-api.x.ai, authorized with a management key. The request body carries an apiKey object with the fields you want and a fieldMask string naming which of those fields apply. The Management API guide shows updates for qpm and name. Create the management key first with Create a management key in the xAI Console if you do not already have one.
What you need
A management key that can update API keys for the team, the apiKeyId from create or list (not the secret string), and a field mask that matches only the properties you intend to change. Neighboring key jobs include Create an xAI API key via the Management API, Rotate an xAI API key via the Management API, and Check API key propagation via the xAI Management API. More API jobs live on the API hub.
Update selected fields
- Export the management key and API key id outside of source control:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_API_KEY_ID="your_api_key_id"
- Update queries per minute, following the guide example:
curl "https://management-api.x.ai/auth/api-keys/${XAI_API_KEY_ID}" \
-X PUT \
-H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}" \
-H "Content-Type: application/json" \
-d '{
"apiKey": {
"qpm": 200
},
"fieldMask": "qpm"
}'
- Rename the key when the display label in Console or list output should change:
curl "https://management-api.x.ai/auth/api-keys/${XAI_API_KEY_ID}" \
-X PUT \
-H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}" \
-H "Content-Type: application/json" \
-d '{
"apiKey": {
"name": "Updated API key"
},
"fieldMask": "name"
}'
- Apply the same pattern for other documented fields inside
apiKey:tpm(string),disabled(boolean),aclStrings(array of ACL strings from the models and endpoints list routes),expireTime, and related rate fields such asqps. SetfieldMaskto the field name you are changing, matching the docs examples (qpm,name,tpm). After an ACL or disable change, confirm clients still behave as expected; a disable stops the key from making API calls without deleting it. When you need a new secret value rather than metadata changes, use Rotate an xAI API key via the Management API instead of this PUT.
Keep every call on https://management-api.x.ai. An inference API key against https://api.x.ai will not update key metadata.
Keep updates in the ops loop
Run PUT updates from the same checklist that lists keys and audits ACLs so field masks never drift from the intended change. After tightening ACLs, re-check grants against List team models via the xAI Management API and List endpoint ACLs via the xAI Management API. Pair with Manage API keys with the xAI Management API when list, create, rotate, and delete sit beside this update job.
Pitfalls
Omitting fieldMask or setting it to a different name than the nested apiKey property leaves the key unchanged while your script reports success. Sending the secret string in the path instead of apiKeyId fails or targets the wrong resource. Using update when you meant rotate never replaces the secret. Broadening aclStrings without pulling current endpoint and model lists from Management invents permissions the team cannot use.