﻿---
title: stack es security update-api-key cli command
description: Update an API key. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4089/reference/elastic-cli/cli/stack/es/security/update-api-key
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es security update-api-key cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es security update-api-key --id <id> [options]
```

Update an API key.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--id string required">
    The ID of the API key to update.
  </definition>
  <definition term="--role-descriptors string">
    The role descriptors to assign to this API key.
    The API key's effective permissions are an intersection of its assigned privileges and the point in time snapshot of permissions of the owner user.
    You can assign new privileges by specifying them in this parameter.
    To remove assigned privileges, you can supply an empty `role_descriptors` parameter, that is to say, an empty object `{}`.
    If an API key has no assigned privileges, it inherits the owner user's full permissions.
    The snapshot of the owner's permissions is always updated, whether you supply the `role_descriptors` parameter or not.
    The structure of a role descriptor is the same as the request for the create API keys API.
  </definition>
  <definition term="--metadata string">
    Arbitrary metadata that you want to associate with the API key.
    It supports a nested data structure.
    Within the metadata object, keys beginning with `_` are reserved for system usage.
    When specified, this value fully replaces the metadata previously associated with the API key.
  </definition>
  <definition term="--expiration string">
    The expiration time for the API key.
    By default, API keys never expire.
    This property can be omitted to leave the expiration unchanged.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>