Visibility: public · internal ( OpenAPI Custom Extension: x-visibility )
Hard-delete (purge) an API key and all associated metadata. This action is irreversible. The key is immediately unusable regardless of its prior status.
Regular users can only delete keys they created. Requests targeting keys owned by other users return 404 to prevent key ID enumeration. Tenant administrators can delete any key within the tenant.
Recommended workflow: disable the key via PATCH first, confirm no active workloads are affected, then delete after the retention period.