Rename a credential or rotate its reference
Renames a credential or rotates the secret it points at, and returns the stored reference; omitted fields keep their current values. An integration credential’s connection cannot be repointed, because that would silently change which account the agent acts as.
Authorizations
A Recursion API key, created in the console under API keys.
Headers
Optional tenant consistency check. When present, it must name the tenant bound to the API key, including when x-organization-id is default.
1Organization in which to act. Required for a tenant-scoped API key. Optional for an organization-scoped key, where it must name that same organization. The value may be an organization id or default.
1Path Parameters
Vault id (UUID) that owns the credential.
Credential reference id (UUID) within the vault, as returned by managedAgentsListVaultCredentials.
Body
Request body for updating one standalone Managed Agents vault credential. Omitted fields keep their current values. credential_type, mcp_server_url and integration_connection_id are fixed at create; sending one is rejected with 400.
Replacement operator-facing label. Omit to keep the current one.
256Replacement permission preset for an integration grant.
Replacement resource allowlist for an integration grant.
Replacement caller-owned labels. Omit to keep the current object.
Replacement environment variable or header name. Omit to keep the current one.
New secret-manager reference. Omit to keep the current secret.
Replacement credential material. Omit to keep the current secret.
Response
OK
RFC 3339 timestamp of when this record was created. Server-assigned.
Identifier for this credential (UUID). Server-assigned, and unique only within its vault.
How the credential is used. Legacy rows may report additional kinds, so this remains a string rather than a closed response enum.
Organization that owns this record. Resolved from the authenticated principal; never accepted from the caller.
RFC 3339 timestamp of the last change to this record. Server-assigned.
Vault this credential belongs to (UUID).
Operator-facing label for the credential.
Organization integration connection this credential grants a session (UUID).
Permission preset applied when a token is minted for this grant.
Resources within the connection the grant is narrowed to.
MCP server this credential may be sent to.
Free-form caller-supplied labels, excluding compatibility metadata reserved by another contract.
Deployment-derived identity of an exact platform MCP service this credential targets; never caller-controlled or stored.
slack_tools Environment variable or header name the secret binds to inside the sandbox.
Pointer to material stored in an external secret manager. Opaque to this service.