Do API keys expire? Sume keys last until revoked

Some API keys expire and many last until revoked. Sume keys have no expiry date in current code, so rotation is on you. How and when to rotate.

4 min readSume
All posts

Whether an API key expires depends on the provider: some keys carry an expiry date, and many keep working until someone revokes them. Sume API keys have no expiry date in current code. A key works until it is revoked, so deciding when to replace it is up to you.

The key behavior below comes from Authentication and API keys on docs.sume.com, read 2026-09-29. The points marked as current code were read from Sume's source the same day and can change.

What does a Sume key record keep track of?

In current code, a key record stores when it was created, when it was last used, and when it was revoked. It has no expiry field and no status that changes with time: a key is either active or revoked. The docs say API responses show key metadata such as id, name, prefix, scopes and last-used time, never the full secret.

From Sume's API key record in current code and Authentication, read 2026-09-29.
What is recordedWhat it tells you
Created timeWhen the key was minted
Last-used timeEmpty until first use; a key unused for months is a candidate to revoke
Revoked timeEmpty while the key is active
Statusactive or revoked
Expiry dateNone: no such field exists

What happens when a key is revoked?

A revoked key is refused with 401 unauthorized, the same status as a missing or malformed key. The fix the docs give is to check the header and create a new key if needed.

  • Revocation is not instant everywhere: in current code the API caches key lookups for 15 seconds by default, so a revoked key can keep working for up to that long.
  • In a team workspace, current code lets Admins revoke any team key; other members can revoke only the keys they created.
  • Revoking your own credential only narrows access, so every role can do it.

Should API keys expire?

A key with no expiry is only as safe as your rotation habit. It stays valid through staff changes, old CI jobs and forgotten laptops unless someone revokes it. Since Sume keys don't lapse on their own, set your own triggers for replacing one:

  • The key appeared in logs or chat history. The docs say to rotate it.
  • The key was exposed. Rotate from the dashboard; Exposed API key? Revoke it, then check what it did walks through the cleanup.
  • You need a scope the key lacks. Scopes are fixed when a key is created, and there is no API to add them later; an older key answers 403 insufficient_scope.
  • Someone who held the key left the project. Separate keys per person or service make this easier; see Can multiple people use the same API key?.
  • The last-used time shows the key is idle. Revoke it.

How do I rotate a Sume API key without downtime?

Because an expired key is never the trigger, a planned rotation is overlap, not a cutover: create a replacement key, deploy it to your server, verify GET /v1/me (it returns the current API key, owner and workspace context, see API reference), then revoke the old key from the dashboard. How Sume API keys work covers the rotation steps and where to keep the key; Exposed API key? covers the emergency version.

Put the replacement date in your own calendar or secret manager at creation time. The key record has no date field that could prompt it for you.

Do API keys change on their own?

No. A Sume key doesn't rotate or regenerate by itself. A different secret, or different scopes, means creating a new key and revoking the old one. The dashboard reveals the full secret only when a key is created, so a lost secret also means a new key.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume