Delete an AccessKey pair to revoke a RAM user's programmatic access. Deleted pairs move to the recycle bin first, where you can restore them or let them auto-purge after 30 days.
Prerequisites
The AccessKey pair is disabled. Disable an AccessKey pair for a RAM user.
Limits
Each RAM user's recycle bin holds up to three AccessKey pairs. Adding a fourth automatically purges the oldest.
Move an AccessKey pair to the recycle bin
Disabled AccessKey pairs can be moved to the recycle bin. Neither disabled nor recycled pairs can make API calls.
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Users page, click the RAM user.
-
On the AccessKey tab, in the AccessKey section, find the AccessKey pair and click Delete in the Actions column.

-
In the Delete dialog box, enter the AccessKey ID and click Move to recycle bin.
Permanently purge an AccessKey pair
Purge methods
-
Automatic purge: Automatically purged after 30 days in the recycle bin.
-
Manual purge: Permanently purge a specific AccessKey pair from the recycle bin.
Impact of purging
Purged AccessKey pairs cannot be restored.
Procedure
-
On the user details page, in the AccessKey Pair Recycle Bin section, find the AccessKey pair and click Delete in the Actions column.

-
In the Delete AccessKey dialog box, enter the AccessKey ID and click Delete.
Restore an AccessKey pair from the recycle bin
Restore a mistakenly deleted AccessKey pair. Restored pairs are automatically re-enabled.
-
If the AccessKey pair's owner is also in the recycle bin, restore the RAM user first. Disable or delete a RAM user.
-
Restoring an AccessKey pair recovers all information except the AccessKey secret, which is shown only at creation.
-
On the user details page, in the AccessKey Pair Recycle Bin section, find the AccessKey pair and click Restore in the Actions column.

-
In the Restore AccessKey Pair dialog box, click Restore.