Skip to main content
PUT
Enable or disable a credential
Requires scope: manage:credentials — see Required scopes. Sets the credential to ACTIVE or DISABLED. Disabling is a pause, not a delete: the credential keeps its clientId, secret and history and simply stops issuing tokens. Re-enabling restores it unchanged.
If Venly provisioned more than one credential for your company before this endpoint existed, disabling one is final — at most one may be active, and restoring a disabled one needs Venly. If a secret is compromised, rotate rather than disable.

Errors

Authorizations

FlowClient Credentials
Token URL
https://login-staging.venly.io/auth/realms/VenlyFinance/protocol/openid-connect/token

Headers

x-tenant-id
string<uuid>

Which tenant the request is scoped to, among those your token grants. Omit it when the token grants exactly one tenant; it is required when the token grants more than one. A supplied value must exactly match a tenant the token grants.

Absent when required, blank, malformed, or naming a tenant the token does not grant — each gets the same generic 403 forbidden, which reveals neither whether a tenant exists nor which ones you may use. Send the header once: a repeated header is rejected the same way.

Example:

"3fa85f64-5717-4562-b3fc-2c963f66afa6"

Path Parameters

clientId
string
required

The credential's OAuth client_id

Body

application/json
status
enum<string>
required

Lifecycle state of a credential. There is no deleted state: revocation is DISABLED, which is reversible and preserves the credential's identity, roles and history.

Available options:
ACTIVE,
DISABLED

Response

Status updated. Never includes a secret.

success
boolean

Indicates whether the request was successful

result
object

A credential as it is read back. This schema has no secret property — the secret is returned only by create and rotate, and cannot be recovered by reading.