> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arena-predictions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate API key

> Replace a key: a new key with the same label and scopes (its token shown once in this response), and the old key kept working for graceSeconds (0 to 86400; 0 revokes it at once). One transaction. A rotating key does not count toward the 10-key cap; a rotation counts toward the 20 keys a day.



## OpenAPI

````yaml /openapi.json post /api_keys/{id}/rotate
openapi: 3.1.0
info:
  title: Arena API
  version: 1.11.0
  summary: >-
    Arena Predictions paper trading with an API key: read, and place paper
    orders with trade:write. Arena-owned data only.
  description: >-
    Arena Predictions (arena-predictions.com) is a sandbox for paper trading
    prediction markets at live prices. Every endpoint here serves Arena's
    sandbox, where every trade is a paper trade (mode "paper"); routing to live
    trading is coming. Keys are read-only and reach Arena-owned data only: the
    key's own identity and account, the leaderboards and published trader
    records with their resets and settled picks. Keys are managed with the
    signed-in browser session, never with a key. No exchange ticker, market
    title, entry price or venue price appears in any keyed response; the owner's
    own portfolio carries the owner's own paper numbers (a resting order's
    limitCents, a position's costDollars and contracts). Balances carry over:
    every account starts with 100,000 paper dollars, and a reset (at most one
    every 30 days, shown on a public profile) starts a new run. 1.2.0: seasons
    removed (no season field anywhere), leaderboard windows and kinds, trader
    resets, GET /account. 1.3.0: accounts are private by default. A private
    trader answers private: true with every P&L and rank null (resets and busts
    0) and an empty pick list; a public trader whose earlier trades are still
    hidden has numbersShown: false and no P&L or rank. The key owner reads their
    own picks (each with placedPrivate and shown) and their own eval rows (GET
    /me/eval) with portfolio:read. No key can make an account public. 1.4.0:
    keys are managed by a person's session, on the website or as a signed-in
    CLI's session token (arena keys), never by a key; keys rotate with a grace
    period; every keyed answer carries the plan and its counts (RateLimit-*,
    Arena-Quota-*, Arena-Plan) and GET /usage says where the account stands; a
    new scope, markets:read, reads instruments, games and quotes; GET /portfolio
    and /portfolio/trades read the owner's positions, orders and trades. Venue
    references and venue prices are served only while the venue-data switch is
    on (it ships off): until then the quotes routes answer 403 venue_data_off
    and nothing keyed names a ticker or a venue's price. 1.5.0: GET /eval, the
    public eval board (records:read), each row with 95% intervals clustered by
    game. 1.6.0: GET /traders/{traderId}/track-record, a trader's Ed25519-signed
    90-day record exactly as Arena signed it (records:read; it names Kalshi
    series inside its signed bytes, so it is served only while the venue-data
    switch is on), and tiedWithAbove on each eval row (null while this row's or
    the row above's interval is unknown). 1.7.0: a key created with trade:write
    (only when asked for by name: the Settings checkbox, arena keys create
    --trade, or scopes in the body) places paper orders with POST
    /portfolio/orders and cancels them with DELETE /portfolio/orders/{orderId},
    at Kalshi's paths. Market and limit orders, buys by instrument or ticker and
    sells of a whole position, each with an idempotencyKey: the same key again
    answers the stored order with replayed: true and places nothing. Hard trade
    limits are always enforced: per key 10 new orders a minute and 50 a day, and
    20 sells and cancels a minute; per account, across every key and connected
    app, 20 new orders a minute, 100 a day, and 40 sells and cancels a minute.
    1.8.0: GET /traders/{traderId}/track-record asks promote-record for
    audience=keyed and is served while the venue-data switch is off
    (records:read). That envelope has the same scores, signed with the same key,
    and names no Kalshi series ticker and no venue. Quotes still answer 403
    venue_data_off until the switch is on. The CLI, the Python SDK and hosted
    MCP verify still read the public envelope, which names series. 1.9.0: POST
    /backtest (markets:read) forwards a paper replay of settled Kalshi
    game-winner markets to the backtest edge function. The JSON body is
    forwarded and the function's JSON is returned, with mode paper. GET and
    every other method answer 405 method_not_allowed and are not forwarded.
    1.10.0: X-Arena-Org, an organization id, on GET /portfolio, GET
    /portfolio/trades, POST /portfolio/orders and DELETE
    /portfolio/orders/{orderId}. When the header is present those calls use that
    organization's paper sandbox. When it is absent they use the key owner's
    personal paper account. A value that is not an organization id is 400
    invalid_request. An unknown organization is 404 organization_not_found and
    one this key cannot use is 403 organization_forbidden. The personal account
    is never the fallback, and the header does not select a Combine evaluation
    account. Paper only. 1.10.1: GET /organizations lists the organizations a
    personal API key belongs to. The call is forwarded to the organizations edge
    function with the caller's key, and the function's JSON is returned with
    mode paper. Each organization's id is what X-Arena-Org takes on the
    portfolio and paper-order routes. Any valid key, no particular scope. Paper
    only. 1.10.2: GET /portfolio and GET /portfolio/trades with X-Arena-Org
    return that organization's paper sandbox (cash, positions, resting orders
    and trades) and organization.slug. They do not return the personal account.
    1.11.0: GET /history, GET /history/candles, GET /history/as_of and GET
    /history/export (markets:read) forward the query string to the Fly history
    service. The caller's key is checked here. The Fly server key stays on the
    server and is sent as x-arena-server-key to /srv/history*. The service's
    JSON is returned unchanged, and export may be CSV. While the venue-data
    switch is off these answer 403 venue_data_off and Fly is not called. A 400
    or a non-auth 403 from the service keeps that status. A Fly 401 (the server
    key was refused) is 503, so a good caller key is not reported invalid. GET
    and HEAD only. Paper only. The keyless website routes
    (/api/quotes/{instrumentId}, /api/quotes/batch, /api/gaps,
    /api/gaps/{instrumentId}) are described in their own document,
    /openapi-public.json.
  termsOfService: https://arena-predictions.com/terms
  contact:
    name: Arena
    email: support@zbgcllc.com
    url: https://arena-predictions.com/support
servers:
  - url: https://arena-predictions.com/api/v1
    description: >-
      The Arena API. Every account on it trades in the sandbox (paper trading);
      routing to live trading is coming.
security: []
tags:
  - name: Status
    description: Is the API up.
  - name: Identity
    description: >-
      Whose account a key acts for, which organizations it belongs to, and what
      it may do.
  - name: API keys
    description: >-
      Create, list, rotate and revoke keys, at the same path Kalshi uses. A
      person's session only (the website, or a signed-in CLI's session token): a
      key can never mint, rotate or revoke a key.
  - name: Records
    description: >-
      Arena's public records: the leaderboards, trader records with their
      resets, and settled picks. Scope records:read. Arena-owned data only: no
      exchange tickers, market titles, entry prices or live prices. Points equal
      paper dollars 1:1.
  - name: Portfolio
    description: >-
      The key owner's own paper account, positions, orders and trades. Scope
      portfolio:read. Send X-Arena-Org to read an organization sandbox instead.
      Arena-owned data only while the venue-data switch is off.
  - name: Markets
    description: >-
      Arena's instruments and games, venue quotes, POST /backtest (a paper
      game-winner replay), and GET /history* (Fly price history). Scope
      markets:read. Venue references, prices and history only while the
      venue-data switch is on.
  - name: Trading
    description: >-
      Place and cancel paper orders for the key owner. Scope trade:write, which
      a key carries only when its creator asked for it. Send X-Arena-Org to
      trade that organization's paper sandbox. Paper is the default: nothing is
      sent to a venue unless execution is kalshi (trade:write:kalshi) or
      poly-intl (trade:write:poly-intl, Polymarket International only).
      Polymarket US is not offered.
  - name: Usage
    description: >-
      Where the key's account stands against its plan. Any valid key; never
      counted.
externalDocs:
  description: Arena API docs
  url: https://docs.arena-predictions.com
paths:
  /api_keys/{id}/rotate:
    post:
      tags:
        - API keys
      summary: Rotate API key
      description: >-
        Replace a key: a new key with the same label and scopes (its token shown
        once in this response), and the old key kept working for graceSeconds (0
        to 86400; 0 revokes it at once). One transaction. A rotating key does
        not count toward the 10-key cap; a rotation counts toward the 20 keys a
        day.
      operationId: rotateApiKey
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KeyRotateRequest'
      responses:
        '201':
          description: Rotated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyRotateResponse'
        '400':
          description: >-
            invalid_request: not same-origin (cookie session), not JSON, the id
            is not a uuid, graceSeconds is out of 0..86400, or expiresInDays is
            out of 1..365.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            unauthorized (not signed in) or session_required (an API key was
            presented).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            guest_account, or scope_not_available (the key carries trade:write
            while trading with keys is switched off).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            key_not_found: not an active key of this account (revoked, expired,
            already rotated, or not yours).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: 'key_creation_limited: 20 keys made in the last 24 hours.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          headers:
            Retry-After:
              $ref: '#/components/headers/Retry-After'
        '500':
          description: Could not rotate the key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
        - sessionBearer: []
components:
  schemas:
    KeyRotateRequest:
      type: object
      properties:
        graceSeconds:
          type: integer
          minimum: 0
          maximum: 86400
          default: 0
          description: How long the old key keeps working. 0 revokes it at once.
        expiresInDays:
          type: integer
          minimum: 1
          maximum: 365
          description: >-
            The new key's life. Omitted: the same life as the old key (at most
            365 days), or none when the old key had none.
    KeyRotateResponse:
      type: object
      required:
        - key
        - token
        - warning
        - replaced
      properties:
        key:
          $ref: '#/components/schemas/KeyView'
        token:
          type: string
          description: The new plaintext key. Shown once; only its hash is stored.
        warning:
          type: string
        replaced:
          $ref: '#/components/schemas/KeyView'
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Stable machine token. Branch on this, never on message.
              enum:
                - invalid_request
                - unauthorized
                - invalid_token
                - insufficient_scope
                - guest_account
                - scope_not_available
                - key_limit_reached
                - key_not_found
                - trader_not_found
                - account_not_found
                - route_not_found
                - method_not_allowed
                - internal_error
                - session_required
                - key_creation_limited
                - rate_limited
                - quota_exceeded
                - venue_data_off
                - instrument_not_found
                - game_not_found
                - membership_required
                - trading_off
                - kalshi_key_missing
                - kalshi_rejected
                - poly_intl_key_missing
                - poly_intl_rejected
                - us_not_eligible
                - not_configured
                - live_trading_unavailable
                - idempotency_key_reused
                - insufficient_balance
                - market_not_found
                - no_tradable_listing
                - market_not_open
                - market_resolved
                - no_liquidity
                - price_moved
                - trade_not_found
                - already_closed
                - order_not_found
                - organization_not_found
                - organization_forbidden
            message:
              type: string
              description: Human sentence. May change.
            retryAfterSeconds:
              type: integer
              minimum: 1
              description: 'On every 429: the same number as the Retry-After header.'
    KeyView:
      type: object
      required:
        - id
        - label
        - tokenPrefix
        - scopes
        - status
        - createdAt
        - lastUsedAt
        - expiresAt
        - revokedAt
        - createdVia
        - rotatedFrom
        - rotatedAt
        - requestsThisMonth
      properties:
        id:
          type: string
          format: uuid
        label:
          type: string
          maxLength: 64
        tokenPrefix:
          type: string
          description: >-
            First 16 characters of the token, for matching a row to a key. Never
            the token.
        scopes:
          type: array
          items:
            type: string
            enum:
              - records:read
              - portfolio:read
              - markets:read
              - trade:write
              - trade:write:kalshi
              - trade:write:poly-intl
        status:
          type: string
          enum:
            - active
            - rotating
            - revoked
            - expired
          description: >-
            rotating: replaced by a rotation and still inside its grace period
            (it works until expiresAt).
        createdAt:
          type: string
          format: date-time
        lastUsedAt:
          type:
            - string
            - 'null'
          format: date-time
          description: Updated at most once an hour.
        expiresAt:
          type:
            - string
            - 'null'
          format: date-time
        revokedAt:
          type:
            - string
            - 'null'
          format: date-time
        createdVia:
          type: string
          enum:
            - web
            - cli
          description: 'web: Settings. cli: arena keys.'
        rotatedFrom:
          type:
            - string
            - 'null'
          format: uuid
          description: The key this one replaced by rotation.
        rotatedAt:
          type:
            - string
            - 'null'
          format: date-time
          description: When this key was rotated.
        requestsThisMonth:
          type: integer
          minimum: 0
          description: Keyed requests counted against this key this month (UTC).
  headers:
    Retry-After:
      description: Seconds to wait before trying again.
      schema:
        type: integer
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: sb-access-token
      description: >-
        The signed-in browser session (Google or Apple). Used only for key
        management, same-origin JSON requests only. An API key presented here is
        refused (401 session_required).
    sessionBearer:
      type: http
      scheme: bearer
      bearerFormat: Supabase access token (JWT) of a signed-in person
      description: >-
        A signed-in CLI's session token (arena login, then arena keys), checked
        with the auth server. Used only for key management; JSON bodies
        required. Never an arena_sk_ key (401 session_required), never a guest
        session (403 guest_account).

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.