As an Organization Admin, disable an API key of an agent belonging to a user in your organization so it no longer authenticates. Keys are never deleted and can be re-enabled later. Deactivating an already-inactive key is a no-op.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
As an Organization Admin, disable an API key of an agent belonging to a user in your organization so it no longer authenticates.
Authenticate with an Organization Admin User API key, sent in the skyfire-api-key header. Keys belonging to Organization Admins are accepted; a MEMBER key, or any Agent API key, is rejected with 401.
The key is resolved through the ownership chain organization → user → agent → API key, all scoped to your own organization. Any link in the chain that does not exist, belongs to another organization, or is mismatched (for example, a valid key ID under a different agent) returns 404.
Keys are never deleted — a deactivated key remains visible in Get Agent API Keys with active: false and can be re-enabled later with Activate Agent API Key. Deactivating a key that is already inactive is a no-op and still returns 204.
Revocation timing
Deactivation is typically immediate. Because authentication results are cached, requests using the deactivated key may continue to succeed for a short window after this call returns; revocation is guaranteed everywhere once the authentication cache expires. For zero-downtime rotation, create the replacement key first, migrate your workload, and deactivate the old key last.
204No Content. The key is deactivated.

