Update a credential
/credentials/{credential_id}Updates the name, purpose, or expires_at of a credential, or changes its status.
Setting status to suspended suspends the credential, and setting it to active reactivates it. inactive is a deprecated alias of suspended. Setting status to revoked permanently revokes the credential; revocation cannot be undone.
Send the ETag returned by the retrieve operation in the If-Match header to avoid overwriting a newer version.
A credential cannot update itself.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Public ID of the credential, prefixed with key_.
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Expected revision of the resource, in the same format as the ETag header (W/"<type>:<id>:<revision>"). If the resource has changed since that revision, the request fails with 412 and the revision_mismatch error code. * matches the current revision. Any other value fails with 400 and the if_match_invalid error code. When omitted, the update is applied to the current revision.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/credentials/string" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "auth_mode": "autonomous", "created_at": "2019-08-24T14:15:22Z", "created_by": { "id": "string", "kind": "admin" }, "environment": "production", "expires_at": "2019-08-24T14:15:22Z", "human": { "admin_id": "string", "eligible_since": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z" }, "id": "string", "name": "string", "object": "credential", "policy": { "active_version": 0, "auth_revision": 0 }, "purpose": "string", "revision": 0, "revoked_at": "2019-08-24T14:15:22Z", "revoked_by": { "id": "string", "kind": "admin" }, "secret": { "configured": true, "issued_at": "2019-08-24T14:15:22Z", "last4": "string", "rotated_at": "2019-08-24T14:15:22Z", "valid_until": "2019-08-24T14:15:22Z", "value": "string", "version": 0 }, "status": "active", "updated_at": "2019-08-24T14:15:22Z" }}Retrieve a credential GET
Retrieves a credential by its public ID. The `secret` object exposes only metadata, such as the last four characters and the rotation date. The secret value itself is never returned by this operation. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when updating the credential to avoid overwriting a newer version.
Delete a credential DELETE
Deletes a revoked or expired credential. After deletion, the credential is no longer returned by the API, while audit records that reference it are preserved. Credentials that are still valid cannot be deleted and return the `state_conflict` error code. Revoke the credential with the update operation first. A credential cannot delete itself.