Skip to main content
HTTP 401 · type authentication. The key was valid once and has been revoked — from the dashboard, or during an incident response. Revocation is immediate and permanent; a revoked key is never reactivated. Nothing ran and nothing was charged.

The shape

revoked_at is when it happened — useful for correlating with a rotation or an incident.

How to fix

  • Switch to a current key. Mint one at platform.fiveninelabs.com if none exists, and update every deployment that held the old one.
  • If you didn’t revoke this key, treat it as a security signal: check the dashboard’s key list (last-used timestamps) and your team.
  • Getting key_revoked rather than invalid_key is deliberate — it tells you your configuration is stale, not wrong.

Reproduce it

Revoke a key in the dashboard (mint a throwaway first), then call anything with it: