Skip to main content
PATCH
Rename a credential, rotate its reference, or change its egress bounds

Authorizations

Authorization
string
header
required

A Recursion API key, created in the console under API keys.

Path Parameters

vault_id
string<uuid>
required

Vault id (UUID) that owns the credential.

credential_id
string<uuid>
required

Credential reference id (UUID) within the vault, as returned by listVaultCredentials.

Body

application/json

Request body for updating one vault credential. Every field is optional and omitted fields keep their current value; the MCP server URL and an integration connection are deliberately not changeable here.

allowed_hosts
string[]

Replacement host allowlist for limited networking, supporting wildcards such as *.example.com. Sent as a whole list, not merged; omit to keep the current one.

display_name
string

Replacement operator-facing label. Omit to keep the current one.

injection_locations
enum<string>[]

Replacement list of where the credential is applied. Sent as a whole list, not merged; omit to keep the current one.

One place a credential is applied to an outbound request. Headers alone is recommended; a secret in a request body is far easier to log by accident.

Available options:
headers,
body
integration_permission
string

Replacement permission preset for an integration grant. The connection itself is not repointable: that would change which account the agent acts as.

integration_resources
string[]

Replacement resource allowlist for an integration grant.

labelbox_scope
object

Replacement Labelbox scope for a credential to the Labelbox product-state service. Sent as a whole object, not merged; omit to keep the current one. It cannot be cleared: delete and recreate the credential instead.

Example:
metadata
object

Replacement free-form caller-owned JSON. Sent as a whole object, not merged; omit to keep the current value. The key labelbox_scope is reserved for the typed field.

network_mode
enum<string>

Replacement network mode. limited confines the credential to allowed_hosts; unrestricted removes that confinement. Omit to keep the current one.

Available options:
limited,
unrestricted
secret_name
string

Replacement environment variable or header name the secret binds to inside the sandbox. Omit to keep the current one.

secret_ref
string

New secret-manager reference, for material stored elsewhere. Not supported for webhook_secret. Omit to keep the current secret.

secret_value
string

Replacement credential material. Stored as a new secret version so the previous value stays revocable. Omit to keep the current secret.

Response

One credential in a vault, described without its secret value — no field on this shape can carry secret material, which is what makes it safe to list over the API. Returned when managing a vault's contents; the value itself is opened only inside a running session.

One credential in a vault, described without its secret value — no field on this shape can carry secret material, which is what makes it safe to list over the API. Returned when managing a vault's contents; the value itself is opened only inside a running session.

created_at
string<date-time>
required

RFC 3339 timestamp of when this record was created. Server-assigned.

credential_id
string
required

Identifier for this credential (UUID). Server-assigned, and unique only within its vault.

credential_type
string
required

How the credential is used: bearer_token, env_var, or webhook_secret. Legacy rows may report mcp_oauth or integration, so this remains a string rather than a closed response enum.

organization_id
string
required

Organization that owns this record. Resolved from the API key; never accepted from the caller.

updated_at
string<date-time>
required

RFC 3339 timestamp of the last change to this record. Server-assigned.

vault_id
string
required

Vault this credential belongs to (UUID).

allowed_hosts
string[]

Hosts the credential may be sent to when network_mode is limited. Ignored under unrestricted.

display_name
string

Operator-facing label for the credential. Optional: a credential is identifiable by its secret_name or MCP server without one.

injection_locations
string[]

Where the credential is attached to an outbound request: headers, body, or both. Headers alone is recommended; a secret in a request body is far easier to log by accident. Meaningful only for the MCP OAuth and bearer-token kinds: env_var is injected into the sandbox environment, and integration mints its own token per session.

integration_connection_id
string

Organization integration connection this credential grants a session (UUID). Set only for the integration kind, where it replaces sealed material: the provider mints a short-lived token per session.

integration_permission
string

Permission preset applied when a token is minted for this grant; see the provider's scope table. An unknown value is rejected on write rather than at mint time.

integration_resources
string[]

Resources within the connection the grant is narrowed to — repositories, for GitHub. Empty means every resource the connection itself can reach, which is broader than most grants should be.

labelbox_scope
object

Labelbox product-state authorization ceiling: either exact projects or organization-wide access, optionally restricted to one exact Slack audience with an explicit internal or Slack Connect classification. Required for a bearer_token credential whose mcp_server_url is that service; rejected for any other server. Replaced as a whole on update and kept when omitted.

Example:
mcp_server_url
string

MCP server this credential may be sent to. Required for bearer_token and immutable afterwards, so a stored secret cannot be repointed at a different service.

metadata
object

Free-form caller-supplied key/value labels. Stored verbatim and never interpreted by the service. The key labelbox_scope is reserved for the typed field of that name.

network_mode
enum<string>

How far the credential may travel: limited confines it to allowed_hosts, unrestricted permits any host. limited is the safe default.

Available options:
limited,
unrestricted
platform_mcp_service
enum<string>

Deployment-derived identity of the exact platform MCP service this credential targets. Present as slack_tools only when mcp_server_url matches the configured Slack tools endpoint; never caller-controlled or stored.

Available options:
slack_tools
secret_name
string

Environment variable or header name the secret binds to inside the sandbox. Required for the env_var kind.

secret_ref
string

Pointer to material stored in an external secret manager, carrying a provider prefix such as kms: or vault:. Opaque to this service, and empty on the normal path where the value is sealed into the credential itself.