Skip to Content
GuidesRotate or Revoke Your Key

Rotate or revoke your key

You manage your API key through the API itself. There is no support mailbox to write to: every action on this page takes effect immediately.

You want toCallProof you own the key
Replace a leaked or old keyPOST /v1/keys/rotateThe current key
Stop a key for goodPOST /v1/keys/revokeThe current key
End a paid subscriptionPOST /v1/keys/revoke with cancel_subscriptionThe current key
Replace a paid key you lostPOST /v1/keys/recover, then POST /v1/keys/recover/confirmYour billing email

Key-management calls are not metered, and they work even when a free key has used its monthly quota.

Rotate a key

Rotation replaces the secret and leaves everything else in place: your plan, rate limit, usage this month, and billing carry over. The old key stops working the moment the call succeeds, so update your secrets manager straight away.

curl -X POST "https://api.creativeforesight.io/v1/keys/rotate" \ -H "Authorization: Bearer $CF_API_KEY"

Where the new key goes depends on how you got the original:

  • Free keys get the new key in the response, just as POST /v1/signup returned the first one. It is shown once.

    { "data": { "key": "cf_live_…", "key_hint": "9f3a61c2", "previous_key_hint": "4b07d1e8", "delivery": "response" }, "meta": { "notice": "Your previous key stopped working immediately. Store this key now …" } }
  • Paid keys never get the new key in the response. It is emailed to the billing address on your subscription, the same way your first key arrived. If someone else has your key, rotating locks them out and the replacement goes only to you.

    { "data": { "key_hint": "9f3a61c2", "previous_key_hint": "4b07d1e8", "delivery": "email", "delivered_to": "b***@example.com" }, "meta": { "notice": "Your previous key stopped working immediately. The new key was emailed …" } }

A key can be rotated 5 times in 24 hours. After that the call returns 429 RATE_LIMIT_EXCEEDED and the current key keeps working.

If a paid key is rotated but the email can’t be sent, the call returns 502 and the old key is already gone. Use recovery to get a working key.

Revoke a key

Revoking is permanent. The key fails authentication immediately and can’t be restored.

curl -X POST "https://api.creativeforesight.io/v1/keys/revoke" \ -H "Authorization: Bearer $CF_API_KEY"
{ "data": { "revoked": true, "key_hint": "4b07d1e8", "subscription_cancelled": false } }

Cancel a paid subscription

A key that pays for an active subscription can’t be revoked on its own, because billing would keep running with no key to use. The call returns 409 SUBSCRIPTION_ACTIVE until you confirm that you want the subscription to end too:

curl -X POST "https://api.creativeforesight.io/v1/keys/revoke" \ -H "Authorization: Bearer $CF_API_KEY" \ -H "Content-Type: application/json" \ -d '{"cancel_subscription": true}'

This cancels the subscription immediately and then revokes the key. The current month’s base fee is not refunded, and any overage you have already used is invoiced. You’ll get an email confirming the subscription has ended.

If you only want to replace a leaked key and keep your plan, rotate it instead.

Recover a lost paid key

If you’ve lost a paid key and no longer have the email it arrived in, prove you own the billing address instead.

  1. Ask for a recovery token:

    curl -X POST "https://api.creativeforesight.io/v1/keys/recover" \ -H "Content-Type: application/json" \ -d '{"email":"billing@example.com"}'

    The answer is always 202, whether or not the address matches a subscription. If it does, an email with a single-use cfr_ token is on its way. The token expires in 30 minutes.

  2. Redeem the token with the command from the email:

    curl -X POST "https://api.creativeforesight.io/v1/keys/recover/confirm" \ -H "Content-Type: application/json" \ -d '{"token":"cfr_…"}'

    Your old key stops working and the new key is emailed to the billing address. The response carries only the key hints.

The token works once. Opening the email doesn’t use it; only the command does. If you didn’t ask for a token, ignore the email and your key keeps working.

Recovery is limited to 10 requests per network per day and 3 tokens per key per hour. Free keys can’t be recovered, because their email address is never verified: create a new one instead.

Billing

  • A payment failed. The payment-failed email links to Stripe’s page for the unpaid invoice, where you can pay with an updated card. Your key keeps working through the 7-day grace period.
  • Your subscription ended. Its key is revoked. To subscribe again, choose a plan on the pricing page .
Last updated on