> ## Documentation Index
> Fetch the complete documentation index at: https://docs.validate.al/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate your API key

> Replaces your API key. The old key stops working at once. Needs a portal session (the API key can't rotate itself) and, when two-factor authentication is on, a current code.



## OpenAPI

````yaml /api-reference/openapi.yaml post /auth/rotate-api-key
openapi: 3.0.3
info:
  title: validate.al API
  description: >-
    Email validation, security scanning and account management, all at
    https://api.validate.al.
  version: '1.0'
servers:
  - url: https://api.validate.al/v1
security:
  - ApiKeyAuth: []
tags:
  - name: Email validation
  - name: Scanning
  - name: Account
  - name: Health
paths:
  /auth/rotate-api-key:
    post:
      tags:
        - Account
      summary: Rotate your API key
      description: >-
        Replaces your API key. The old key stops working at once. Needs a portal
        session (the API key can't rotate itself) and, when two-factor
        authentication is on, a current code.
      operationId: rotateApiKey
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                totp_code:
                  type: string
                  description: Required when two-factor authentication is on.
      responses:
        '200':
          description: New key.
          content:
            application/json:
              schema:
                type: object
                properties:
                  api_key:
                    type: string
                    example: val-0123456789abcdef0123456789abcdef
        '401':
          description: No portal session.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Two-factor code missing or wrong.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    Error:
      description: Errors from scanning and account endpoints.
      type: object
      properties:
        detail:
          type: string
          description: Error message
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: Your validate.al API key, from the portal (Settings → API Key).
    BearerAuth:
      type: http
      scheme: bearer
      description: JWT from sign-in or registration.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.