Skip to content

API key revoked

HTTP 401api_key_revoked

When the API answers 401 api_key_revoked, and how to fix it.

Version v1.1, updated

The type field of every api_key_revoked response links to this page.

On this page

The key was revoked in BIRP, so it no longer works for any request. A revoked key never works again.

At a glance

  • Status: 401 Unauthorized

  • Code: api_key_revoked

  • Retry: No. Fix the cause first: the same request gets the same answer.

Causes and fixes

Likely cause

How to fix it

An administrator of the company revoked the key, for example after a team change or a suspected leak.

Create a new key with the scopes the system needs, and give it to the system.

The system still holds an old key after a rotation.

Replace the key in the secrets manager of that system. Restart the system if it reads the key only at start.

The key list in BIRP shows when a revoked key is still being tried. The key name tells you which system still holds it.

Example

401 api_key_revokedJSON
{
  "code": "api_key_revoked",
  "detail": "The API key has been revoked. Create a new key in BIRP settings.",
  "instance": "/v1/categories",
  "request_id": "a1b2c3d4-0000-4000-8000-0000000000ee",
  "status": 401,
  "title": "API key revoked",
  "type": "https://birp.io/developers/errors/api_key_revoked"
}
  • first-key
  • keep-your-key-safe
  • api-key-expired