> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.superpath.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to Revoke an API Key


# How to Revoke an API Key

**In this article:**
* Overview
* How to revoke an API key
* Things to keep in mind
* FAQs
* Who can do this

## Overview
Revoking an API key immediately disables it. Any app or service using that key to call the SuperPath API will have its requests rejected from that point on. Revoke a key when it's no longer needed, or straight away if you suspect it has been compromised. Revoking can't be undone — if you still need API access, generate a new key.

> **Note:** API keys are only available on paid accounts. On a free plan the **API keys** section shows a message that access to the SuperPath API is only available for paid accounts, with a link to your **Billing settings**.

## How to revoke an API key
1. Go to **Settings → Integrations**.
2. Scroll to the **API keys** section. Each key is listed with its **Name**, **Author**, **Status** and **Last modified** date.
3. Find the active key you want to revoke and click **Revoke** in its row.

![](https://storage.googleapis.com/superpath-help-centre/how-to-revoke-an-api-key/01-keys-table-revoke-action_a5e58ef1.png)

4. In the confirmation window — *"Are you sure you want to revoke this API Key?"* with the warning that all integrations and third-party services using the key will no longer have access to SuperPath, and that the action is not reversible — click **Confirm revoke**. To back out, click **No thanks**.

![](https://storage.googleapis.com/superpath-help-centre/how-to-revoke-an-api-key/02-revoke-confirm-modal_03fc2476.png)

The key is disabled immediately. It stays in the keys table with a revoked status.

## Things to keep in mind
* Revoking takes effect straight away — any API calls made with the key after that will be rejected.
* Revoking **can't be undone**. If you still need API access, generate a new key.
* Only **active** keys show the **Revoke** action. Revoked keys remain listed with a revoked status for your records.
* If a key may have been exposed, revoke it promptly and generate a replacement.

## FAQs
**Can I un-revoke a key?**
No. Revoking is permanent. If you need API access again, generate a new key.

**What happens to apps using the key when I revoke it?**
Their requests to the SuperPath API will be rejected. Update those apps with a new key to restore access.

**Why is a revoked key still showing in the list?**
Revoked keys stay in the table with a revoked status so you have a record of them. They can no longer be used to access the API.

## Who can do this
Only **Owners** and **Admins** can revoke API keys, and only on a paid plan. All Settings pages, including Integrations, are restricted to Owners and Admins — **Managers**, **People Managers**, **Content Managers**, **Instructors**, **Employees** and **Restricted** users cannot access them.
