> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datris.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate the field protection encryption key

> Issues a new version of the environment's `encrypt` key and makes it current; runs after this encrypt with the new version (`enc:v<n>:`). Older versions stay in the secret, so values encrypted with them still reveal. The `hmac` key is never rotated. Needs `protect:admin`. Recorded in the audit log as `key / rotate` with resource `field-protection`.



## OpenAPI

````yaml /openapi.yaml post /api/v1/protect/keys/rotate
openapi: 3.0.3
info:
  title: Datris API
  description: >
    REST API for the Datris AI Data Platform. Ingest, validate, transform,
    store, and retrieve data.


    For AI agent integration, use the [MCP
    Server](https://docs.datris.ai/mcp-server) instead.
  version: 1.28.0
  contact:
    name: Datris
    url: https://datris.ai
  license:
    name: Apache 2.0
servers:
  - url: http://localhost:8080
    description: Local development
security:
  - ApiKeyAuth: []
paths:
  /api/v1/protect/keys/rotate:
    post:
      tags:
        - Pipelines
      summary: Rotate the field protection encryption key
      description: >-
        Issues a new version of the environment's `encrypt` key and makes it
        current; runs after this encrypt with the new version (`enc:v<n>:`).
        Older versions stay in the secret, so values encrypted with them still
        reveal. The `hmac` key is never rotated. Needs `protect:admin`. Recorded
        in the audit log as `key / rotate` with resource `field-protection`.
      responses:
        '200':
          description: The new current version
          content:
            application/json:
              schema:
                type: object
                properties:
                  version:
                    type: integer
        '403':
          description: The caller lacks `protect:admin`
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Optional API key for authentication (enabled via application.yaml)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.