﻿---
title: stack es security bulk-update-api-keys cli command
description: Bulk update API keys. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4089/reference/elastic-cli/cli/stack/es/security/bulk-update-api-keys
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es security bulk-update-api-keys cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es security bulk-update-api-keys --ids <ids> [options]
```

Bulk update API keys.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--ids string required">
    The API key identifiers.
    **Repeatable:** pass `--ids` multiple times to supply more than one value
  </definition>
  <definition term="--expiration string">
    Expiration time for the API keys.
    By default, API keys never expire.
    This property can be omitted to leave the value unchanged.
  </definition>
  <definition term="--metadata string">
    Arbitrary nested metadata to associate with the API keys.
    Within the `metadata` object, top-level keys beginning with an underscore (`_`) are reserved for system usage.
    Any information specified with this parameter fully replaces metadata previously associated with the API key.
  </definition>
  <definition term="--role-descriptors string">
    The role descriptors to assign to the API keys.
    An API key's effective permissions are an intersection of its assigned privileges and the point-in-time snapshot of permissions of the owner user.
    You can assign new privileges by specifying them in this parameter.
    To remove assigned privileges, supply the `role_descriptors` parameter as an empty object `{}`.
    If an API key has no assigned privileges, it inherits the owner user's full permissions.
    The snapshot of the owner's permissions is always updated, whether you supply the `role_descriptors` parameter.
    The structure of a role descriptor is the same as the request for the create API keys API.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>