Skip to main content
PATCH
Rename a credential or rotate its reference

Authorizations

Authorization
string
header
required

A Recursion API key, created in the console under API keys.

Headers

x-tenant-id
string

Optional tenant consistency check. When present, it must name the tenant bound to the API key, including when x-organization-id is default.

Minimum string length: 1
x-organization-id
string

Organization in which to act. Required for a tenant-scoped API key. Optional for an organization-scoped key, where it must name that same organization. The value may be an organization id or default.

Minimum string length: 1

Path Parameters

vaultId
string<uuid>
required

Vault id (UUID) that owns the credential.

credentialId
string<uuid>
required

Credential reference id (UUID) within the vault, as returned by managedAgentsListVaultCredentials.

Body

application/json

Request body for updating one standalone Managed Agents vault credential. Omitted fields keep their current values. credential_type, mcp_server_url and integration_connection_id are fixed at create; sending one is rejected with 400.

display_name
string

Replacement operator-facing label. Omit to keep the current one.

Maximum string length: 256
integration_permission
string

Replacement permission preset for an integration grant.

integration_resources
string[]

Replacement resource allowlist for an integration grant.

metadata
object

Replacement caller-owned labels. Omit to keep the current object.

secret_name
string

Replacement environment variable or header name. Omit to keep the current one.

secret_ref
string

New secret-manager reference. Omit to keep the current secret.

secret_value
string

Replacement credential material. Omit to keep the current secret.

Response

OK

created_at
string<date-time>
required

RFC 3339 timestamp of when this record was created. Server-assigned.

credential_id
string
required

Identifier for this credential (UUID). Server-assigned, and unique only within its vault.

credential_type
string
required

How the credential is used. Legacy rows may report additional kinds, so this remains a string rather than a closed response enum.

organization_id
string
required

Organization that owns this record. Resolved from the authenticated principal; never accepted from the caller.

updated_at
string<date-time>
required

RFC 3339 timestamp of the last change to this record. Server-assigned.

vault_id
string
required

Vault this credential belongs to (UUID).

display_name
string

Operator-facing label for the credential.

integration_connection_id
string

Organization integration connection this credential grants a session (UUID).

integration_permission
string

Permission preset applied when a token is minted for this grant.

integration_resources
string[]

Resources within the connection the grant is narrowed to.

mcp_server_url
string

MCP server this credential may be sent to.

metadata
object

Free-form caller-supplied labels, excluding compatibility metadata reserved by another contract.

platform_mcp_service
enum<string>

Deployment-derived identity of an exact platform MCP service this credential targets; never caller-controlled or stored.

Available options:
slack_tools
secret_name
string

Environment variable or header name the secret binds to inside the sandbox.

secret_ref
string

Pointer to material stored in an external secret manager. Opaque to this service.