Skip to main content

Replace legacy API keys

On 16 November 2026, leftover live legacy API keys will stop working. Create a scoped key, rotate the secret, then archive the old key.

Written by Product Team

Deadline: 16 November 2026. After this date, leftover live (not archived) legacy API keys will stop working. If you cannot finish before the deadline, contact Spare support about an extension.

If your organization still uses a legacy API key, that key has full administrator access. Create a new scoped API key, put the new secret in every integration that used the old one, then archive the legacy key.

  • Scoped keys — created with one or more permission sets. They only perform the actions you grant. New keys are always scoped.

  • Legacy keys — created before scoped permissions. They still have administrator access, show as Legacy in the Type column, and cannot have their permissions edited in place.


Who needs to act

You only need to rotate keys if your organization has at least one active (not archived) legacy API key. On Settings → API Keys, those keys show as Legacy in the Type column.
​

Spare automatically archives API keys that have not been used or changed for 45 days (legacy and scoped). Archived keys cannot authenticate. They do not need a new secret unless you still rely on that integration. On the archived list, these show the reason Not used for 45 days.

Note: You cannot convert a live legacy key to a scoped key while keeping the same secret. Create a new key and replace the secret everywhere it is used (scripts, partners, CI, and other systems).


How to replace a legacy API key

Go to Settings → API Keys.

1. Create a scoped key

Click Create New API Key. Give it a clear name, then select the permission sets the integration actually needs. Copy the secret when it is shown — Spare cannot show it again later.

For permission details, see Scoped API Key Permissions.

2. Rotate the secret

Update every system that used the old key so it uses the new secret. Confirm those calls succeed before you archive the old key.

3. Archive the legacy key

Open the legacy key and archive it. An archived key cannot authenticate.

If you cannot meet the deadline:

If you cannot replace the key in time, contact Spare support about an extension before 16 November 2026.


What happens on 16 November 2026

Any leftover active (not archived) legacy API keys are deactivated. They will no longer authenticate.

After that date, organization administrators cannot unarchive legacy keys. For a limited time period, Spare super admins can still unarchive a legacy key for unusual recovery cases.

Note: Spare emails administrators of organizations that still have a live legacy key, with a link to this article.


Frequently Asked Questions

Do I need to replace every API key?

No. Only active legacy keys. Scoped keys and archived keys are not part of this sunset.

Why is my unused API key archived?

Spare archives keys that have not authenticated or been changed for 45 days. You can unarchive a scoped key if you still need it. Do not unarchive a legacy key to keep using it; create a scoped key instead.

Can I keep using the same secret?

No. You must create a new scoped key and update every place the old secret is stored.

What if I miss the deadline?

Live legacy keys will stop working on 16 November 2026. Create a scoped key and rotate immediately. Contact Spare support only if you cannot recover on your own.

Did this answer your question?