﻿---
title: stack es security update-cross-cluster-api-key cli command
description: Update a cross-cluster API key. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4116/reference/elastic-cli/cli/stack/es/security/update-cross-cluster-api-key
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es security update-cross-cluster-api-key cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es security update-cross-cluster-api-key \
  --access <access> \
  --id <id> \
  [options]
```

Update a cross-cluster API key.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--access string required">
    The access to be granted to this API key.
    The access is composed of permissions for cross cluster search and cross cluster replication.
    At least one of them must be specified.
    When specified, the new access assignment fully replaces the previously assigned access.
  </definition>
  <definition term="--id string required">
    The ID of the cross-cluster API key to update.
  </definition>
  <definition term="--expiration string">
    The expiration time for the API key.
    By default, API keys never expire. This property can be omitted to leave the value unchanged.
  </definition>
  <definition term="--metadata string">
    Arbitrary metadata that you want to associate with the API key.
    It supports nested data structure.
    Within the metadata object, keys beginning with `_` are reserved for system usage.
    When specified, this information fully replaces metadata previously associated with the API key.
  </definition>
  <definition term="--certificate-identity string">
    The certificate identity to associate with this API key.
    This field is used to restrict the API key to connections authenticated by a specific TLS certificate.
    The value should match the certificate's distinguished name (DN) pattern.
    When specified, this fully replaces any previously assigned certificate identity.
    To clear an existing certificate identity, explicitly set this field to `null`.
    When omitted, the existing certificate identity remains unchanged.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>