VideohatiDocs
API referenceProjects

Rotate the project's embed token key

Rotate the project's embed token key

POST/v1/projects/{id}/security-settings/rotate-embed-key

This operation supports dashboard session-cookie authentication. Call it only from trusted server code; browsers must not manufacture or expose the session cookie.

Replaces the embed token key immediately: tokens signed with the old key stop verifying on the spot, and every embed URL must be re-signed with the returned key. Session-cookie auth only. Rate limit: 10 requests per 60 s per session.

Error codes: unauthorized (401), not_found (404), embed_tokens_unconfigured (503).

Authentication

  • sessionCookie — Dashboard session cookie set by POST /v1/auth/login. Video and playback endpoints additionally require the projectId query parameter under cookie auth.

Parameters

NameInTypeRequiredDescription
idpathstring (Ulid)Yes

Request body

This operation takes no request body.

Responses

StatusMeaning
200The new raw embed token key.
401No valid credential was presented.
404The resource does not exist or is not visible to this caller.
429Rate limit exceeded.
503Embed token verification is not configured on this API.