Skip to content
POST
/v1/organizations/{organizationId}/provider-applications/{providerApplicationId}/credential-rotations

Rotate a provider application's write-only credential

Replace the provider application's signing secret only when the supplied credential-generation ETag is current.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
string
All of
  • maximum length 64
A Cantora Organization identifier, prefixed with `org_`.
  • pattern ^org_[\s\S]+$
providerApplicationIdpathYes
The Organization-owned provider application to address.
string
All of
  • maximum length 64
A Cantora provider application identifier, prefixed with `provider_app_`.
  • pattern ^provider_app_[\s\S]+$
if-matchheaderYes
The current strong resource ETag, including its double quotes.
string
All of
  • maximum length 12
  • pattern ^"(?:[1-9][0-9]{0,9})"$

Request body

Required.

application/json
object
  • unknown properties allowed false
signingSecretrequired
stringThe write-only replacement provider secret used to verify signed webhook requests.
  • write only true
All of
  • minimum length 1
  • maximum length 8192

Responses

200ProviderApplication
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json
412ProviderCredentialPreconditionFailed

Reusable schemas

ProviderApplicationJsonEncoding

object
  • unknown properties allowed false
providerApplicationIdrequired
stringThe Organization-owned provider application identifier.
All of
  • maximum length 64
A Cantora provider application identifier, prefixed with `provider_app_`.
  • pattern ^provider_app_[\s\S]+$
organizationIdrequired
stringThe Organization identifier.
All of
  • maximum length 64
A Cantora Organization identifier, prefixed with `org_`.
  • pattern ^org_[\s\S]+$
providerrequired
stringThe model or Surface provider key.
  • allowed values "slack"
providerAppIdrequired
stringThe provider's stable application identifier.
displayNamerequired
stringThe human-readable resource name.
credentialGenerationrequired
integerThe current credential generation, incremented on rotation.
All of
  • greater than 0
credentialEtagrequired
stringThe strong ETag for the current provider-credential generation.
All of
  • maximum length 12
  • pattern ^"(?:[1-9][0-9]{0,9})"$
statusrequired
stringThe current lifecycle status.
  • allowed values "active", "disabled"
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time

UnauthorizedJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ProviderCredentialPreconditionFailedJsonEncoding

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "ProviderCredentialPreconditionFailed"
resourcerequired
stringThe resource type relevant to the error.
  • allowed values "providerApplication"
currentEtagrequired
stringThe current strong ETag required for the next provider-credential rotation.
All of
  • maximum length 12
  • pattern ^"(?:[1-9][0-9]{0,9})"$