Replace a key's permissions.
No API key can call this. keys:update is deliberately not grantable to any
key — editing keys is a human, dashboard-only action — so a bearer token
always gets 403 here, permanently and by design. Use the dashboard’s key
editor instead. The list you send replaces the key’s grants outright rather
than adding to them, and keys seeded from configuration cannot be edited.
Authorizations
A scoped AgentEye API key. Mint one in the dashboard under Settings → API keys, or with POST /v1/keys. Each endpoint names the permission it requires; a key without it gets 403 and a required_permission field naming what was missing.
Path Parameters
The key's id, as returned by GET /keys.
Body
The key's complete new permission list — it REPLACES the old one.
Response
The key's metadata with its new permissions.

