AAC Docs

aac tenant reissue-api-key

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Replace a lost or suspected-compromised tenant API key.

Synopsis

aac tenant reissue-api-key
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  [--tenant-id TENANT_ID]
  [--registration-request-id REGISTRATION_REQUEST_ID]
  [--bootstrap-token BOOTSTRAP_TOKEN]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--tenant-id value no — Tenant to reissue (defaults to the selected profile identity).
--registration-request-id value no — Completed treq-* locator; required only with operator-assisted onboarding recovery and never an authorizer.
--bootstrap-token value no — AAC Ops ceremony credential for operator-assisted onboarding recovery. Falls back to $AAC_BOOTSTRAP_TOKEN. Ordinary tenant administrators omit this and use their cached AAC session.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

Immediate replacement: every ACTIVE tenant API key is revoked atomically and one new key is returned exactly once. There is no grace window and this is NOT tenant-admin Ed25519-key rotation. If a response is lost, run this command again; the new attempt revokes the unknown result. The CLI never retries automatically. Ordinary use requires the tenant's tenant-admin AAC session. During initial onboarding only, AAC Ops may use an explicitly opened ceremony with both --bootstrap-token and the matching --registration-request-id. The registration id locates the tenant and never authorizes the operation.