POST
/v1/organizations/{organizationId}/provider-applications/{providerApplicationId}/credential-rotationsRotate a provider application's write-only credential
Replace the provider application's signing secret only when the supplied credential-generation ETag is current.
Authentication
Send an API key as a Bearer token in the Authorization header.
Parameters
Request body
Required.
application/jsonobject- unknown properties allowed
false
signingSecretrequiredstringThe write-only replacement provider secret used to verify signed webhook requests.- write only
true
All of- minimum length
1
- maximum length
8192
- write only
Responses
200ProviderApplicationapplication/json400The request path, headers, query, or JSON body did not satisfy the published schema401Unauthorizedapplication/json403Forbiddenapplication/json404NotFoundapplication/json412ProviderCredentialPreconditionFailedapplication/jsonReusable schemas
ProviderApplicationJsonEncoding
object- unknown properties allowed
false
providerApplicationIdrequiredstringThe Organization-owned provider application identifier.All of- maximum length
64
A Cantora provider application identifier, prefixed with `provider_app_`.- pattern
^provider_app_[\s\S]+$
- maximum length
organizationIdrequiredstringThe Organization identifier.All of- maximum length
64
A Cantora Organization identifier, prefixed with `org_`.- pattern
^org_[\s\S]+$
- maximum length
providerrequiredstringThe model or Surface provider key.- allowed values
"slack"
- allowed values
providerAppIdrequiredstringThe provider's stable application identifier.displayNamerequiredstringThe human-readable resource name.credentialGenerationrequiredintegerThe current credential generation, incremented on rotation.All of- greater than
0
- greater than
credentialEtagrequiredstringThe strong ETag for the current provider-credential generation.All of- maximum length
12
- pattern
^"(?:[1-9][0-9]{0,9})"$
- maximum length
statusrequiredstringThe current lifecycle status.- allowed values
"active", "disabled"
- allowed values
createdAtrequiredstringWhen the resource was created, in UTC.- format
date-time
- format
UnauthorizedJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Unauthorized"
- allowed values
reasonrequiredstringA safe explanation of why the credential was rejected.
ForbiddenJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Forbidden"
- allowed values
permissionrequiredstringThe permission required by the refused operation.
NotFoundJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"NotFound"
- allowed values
resourcerequiredstringThe resource type relevant to the error.idrequiredstringThe identifier supplied for the resource that was not found.
ProviderCredentialPreconditionFailedJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"ProviderCredentialPreconditionFailed"
- allowed values
resourcerequiredstringThe resource type relevant to the error.- allowed values
"providerApplication"
- allowed values
currentEtagrequiredstringThe current strong ETag required for the next provider-credential rotation.All of- maximum length
12
- pattern
^"(?:[1-9][0-9]{0,9})"$
- maximum length