Remove a credential policy
/credentials/{credential_id}/policies/{policy_id}Removes a policy from a credential. The change publishes a new policy revision containing all remaining policies.
Removing the last policy is allowed and leaves the credential without access to any resource.
A credential cannot modify its own policies, and the policies of a revoked credential cannot be changed (credential_revoked).
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Public ID of the credential, prefixed with key_.
Public ID of the policy, prefixed with pol_.
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/credentials/string/policies/string"Update a credential policy PATCH
Replaces the capabilities and resources of a policy. The change publishes a new policy revision in which the other policies remain unchanged. The policy keeps the same `policy_id` across revisions. Send the `ETag` returned by the retrieve operation in the `If-Match` header to avoid overwriting a newer version. Permissions that the calling credential cannot delegate are rejected with `delegation_limit_exceeded`, and no new revision is published. A credential cannot modify its own policies, and the policies of a revoked credential cannot be changed (`credential_revoked`).
Rotate a credential secret POST
Generates a new secret for the credential. The credential ID and its policies do not change. The previous secret remains valid for an overlap period, set by `overlap_hours` (1 to 168 hours, default 24), so integrations can switch to the new secret without downtime. The new secret is returned only in this response and cannot be retrieved again. Store it securely. Retrying the request with the same `Idempotency-Key` does not return the secret again; it returns `409` with the `secret_not_replayable` error code.