Skip to main content
POST
Rotate a credential's secret
Requires scope: manage:credentials — see Required scopes. Generates a new secret and returns it in this response only. The previous secret stops working immediately, so rotate only when the new value can be deployed at once. Tokens already issued against the old secret remain valid until they expire. Rotation is refused on a DISABLED credential — enable it first.

Errors

Authorizations

FlowClient Credentials
Token URL
https://login-staging.venly.io/auth/realms/VenlyFinance/protocol/openid-connect/token

Headers

x-tenant-id
string<uuid>

Which tenant the request is scoped to, among those your token grants. Omit it when the token grants exactly one tenant; it is required when the token grants more than one. A supplied value must exactly match a tenant the token grants.

Absent when required, blank, malformed, or naming a tenant the token does not grant — each gets the same generic 403 forbidden, which reveals neither whether a tenant exists nor which ones you may use. Send the header once: a repeated header is rejected the same way.

Example:

"3fa85f64-5717-4562-b3fc-2c963f66afa6"

Path Parameters

clientId
string
required

The credential's OAuth client_id

Response

Secret rotated. The new secret is present in this response only.

success
boolean

Indicates whether the request was successful

result
object

A credential together with its secret. Returned by create and rotate only. Record the secret immediately: Finance does not store it, no endpoint returns it afterwards, and a lost secret is replaced by rotating the credential rather than by reading it.