POST
/v1/organizations/{organizationId}/integration-applications/{integrationApplicationId}/credential-rotationsRotate an integration application's write-only credential
Replace the OAuth application's client secret only when the supplied credential-generation ETag is current.
Authentication
Send an API key as a Bearer token in the Authorization header.
Parameters
Request body
Required.
application/jsonobject- unknown properties allowed
false
clientSecretrequiredstringThe write-only replacement OAuth client secret used for token exchange and refresh.- maximum length
8192 - minimum length
1 - write only
true
- maximum length
Responses
200IntegrationApplicationapplication/json400The request path, headers, query, or JSON body did not satisfy the published schema401Unauthorizedapplication/json403Forbiddenapplication/json404NotFoundapplication/json412ProviderCredentialPreconditionFailedapplication/jsonReusable schemas
IntegrationApplicationEncoded
object- unknown properties allowed
false
integrationApplicationIdrequiredstringThe Organization-owned integration application identifier.- maximum length
64 - pattern
^integration_app_[\s\S]+$
- maximum length
organizationIdrequiredstringThe Organization identifier.- maximum length
64 - pattern
^org_[\s\S]+$
- maximum length
providerrequired- IntegrationProviderThe model, Surface, or integration provider key.
providerClientIdrequiredstringThe provider's stable OAuth client identifier.displayNamerequiredstringThe human-readable resource name.credentialGenerationrequiredintegerThe current credential generation, incremented on rotation.- greater than
0
- greater than
credentialEtagrequiredstringThe strong ETag for the current provider-credential generation.- maximum length
12 - pattern
^"(?:[1-9][0-9]{0,9})"$
- maximum length
statusrequired- IntegrationApplicationStatusThe current lifecycle status.
createdAtrequiredstringWhen the resource was created, in UTC.- format
date-time
- format
UnauthorizedEncoded
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Unauthorized"
- allowed values
reasonrequiredstringA safe explanation of why the credential was rejected.
ForbiddenEncoded
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Forbidden"
- allowed values
permissionrequiredstringThe permission required by the refused operation.
NotFoundEncoded
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"NotFound"
- allowed values
resourcerequiredstringThe resource type relevant to the error.idrequiredstringThe identifier supplied for the resource that was not found.
ProviderCredentialPreconditionFailedEncoded
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"ProviderCredentialPreconditionFailed"
- allowed values
resourcerequiredstringThe resource type relevant to the error.- allowed values
"integrationApplication", "providerApplication"
- allowed values
currentEtagrequiredstringThe current strong ETag required for the next provider-credential rotation.- maximum length
12 - pattern
^"(?:[1-9][0-9]{0,9})"$
- maximum length
IntegrationProvider
string- allowed values
"gmail", "googleCalendar", "twitter"
IntegrationApplicationStatus
string- allowed values
"active", "disabled"