Rotate a credential secret
/credentials/{credential_id}/secret-rotationsGenerates a new secret for the credential. The credential ID and its policies do not change.
The previous secret remains valid for an overlap period, set by overlap_hours (1 to 168 hours, default 24), so integrations can switch to the new secret without downtime.
The new secret is returned only in this response and cannot be retrieved again. Store it securely. Retrying the request with the same Idempotency-Key does not return the secret again; it returns 409 with the secret_not_replayable error code.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Public ID of the credential, prefixed with key_.
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Required by this operation: a missing key returns idempotency_key_required, and a malformed key returns idempotency_key_invalid. Repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/credentials/string/secret-rotations" \ -H "Idempotency-Key: string" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "object": "secret_rotation", "rotated_at": "2019-08-24T14:15:22Z", "secret": "string" }}Remove a credential policy DELETE
Removes a policy from a credential. The change publishes a new policy revision containing all remaining policies. Removing the last policy is allowed and leaves the credential without access to any resource. A credential cannot modify its own policies, and the policies of a revoked credential cannot be changed (`credential_revoked`).
Sandbox5
Next Page