Rotate Access Key secret | Tigris Object Storage Documentation

Rotate Access Key secret

POST https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/key/rotate

Rotates the access key secret for a user. The old secret will be invalidated, and the new secret will be returned in the response.

Request

Path Parameters

provider_id string required

Provider ID

org_id string required

Organization ID

Body required

user_id string required

ID of the user for whom the access key is being updated

id string required

Access key ID

user_role OrgMembership

Role of the user in the organization. Controls what the user can do through the Partner API management endpoints.

If omitted, defaults to Member behavior.

Possible values: [Admin, Member]

{
  "user_id": "string",
  "id": "string",
  "user_role": "Admin"
}

Responses

OK

Schema

new_secret string

Rotated access key secret

{
  "new_secret": "string"
}

Unexpected error

Schema

message string

{
  "message": "string"
}

Authorization: X-Tigris-Signature

name: X-Tigris-Signature
(type: apiKey)
(in: header)
(description: HMAC-SHA256 of the canonical request signed using the signing key.)
To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between.
Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:

Create the `canonical_request` as:

POST https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision 1731703213870 f8d133cb-5a42-47b1-9ef2-874bb55bab72

Then, calculate HMAC-SHA256 of the canonical request using the signing key as:

Signature = hex(sha256sign(canonical_request, "signing_key"))



name: X-Tigris-Nonce (type: apiKey) (in: header) (description: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72")


name: X-Tigris-Time (type: apiKey) (in: header) (description: Unix timestamp in milliseconds of the request. Example: 1731703213870)


- csharp
- curl
- dart
- go
- http
- java
- javascript
- kotlin
- c
- nodejs
- objective-c
- ocaml
- php
- postman-cli
- powershell
- python
- r
- ruby
- rust
- shell
- swift

- HTTPCLIENT
- RESTSHARP

```csharp
var client = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Post, "https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/key/rotate");
request.Headers.Add("Accept", "application/json");
request.Headers.Add("X-Tigris-Signature", "<X-Tigris-Signature>");
request.Headers.Add("X-Tigris-Nonce", "<X-Tigris-Nonce>");
request.Headers.Add("X-Tigris-Time", "<X-Tigris-Time>");
var content = new StringContent("{\n  \"user_id\": \"string\",\n  \"id\": \"string\",\n  \"user_role\": \"Admin\"\n}", null, "application/json");
request.Content = content;
var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());

RequestCollapse all

Base URL

Edit

https://mgmt.storage.dev

Auth

Signature

Nonce

Timestamp

Parameters

provider_id — path required

org_id — path required

Body required

{
  "user_id": "string",
  "id": "string",
  "user_role": "Admin"
}

Send API Request

ResponseClear

Click the Send API Request button above and see the response here!