# Change a tool credential

> PATCH /v1/vault/secrets/{secret_id}

Send a new value, a new name or label, or the whole list of projects that may use it. A new value is used from the next request any tool makes. Needs `vault:write` and a live key.

## Parameters

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `secret_id` | path | string (uuid) | Yes |  |

## Body

Sent as JSON. A field this operation does not take is refused, so a typo fails loudly.

| Field | Type | Required | Description |
|---|---|---|---|
| `name` | string or null | No |  |
| `project_ids` | array of string (uuid) or null | No | The whole list of projects again. |
| `provider` | string or null | No | Your own label for whose it is. |
| `secret` | string or null | No | A new value, replacing the old. |

## Answer

`200` with [VaultSecretObject](/reference/objects/VaultSecretObject).

## Errors

Every error is a [problem document](/errors) with a stable `code`.

| Status | When |
|---|---|
| `401` | The key is missing, mistyped, unknown, revoked or expired. |
| `403` | The key lacks a permission, a live key was sent from a browser, or the organization is frozen and the request would change something. |
| `404` | This key reaches no such credential, or a project named is not here. |
| `409` | The credential is revoked, or another one has that name. |
| `422` | Validation Error |
| `429` | Too many requests for this key or its organization; see `Retry-After`. |
| `500` | Something went wrong on our side. Quote the `request_id` to support. |

## Examples

**curl**

```sh
#!/bin/sh
# Rotate a tool credential. Tools send the new value from their next request.
curl -sS --fail-with-body -X PATCH "https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca" \
  -H "Authorization: Bearer $AIGENTLY_API_KEY" \
  --json '{
  "secret": "your-new-orders-api-token"
}'
```

**JavaScript**

```js
// Rotate a tool credential. Tools send the new value from their next request.
const response = await fetch("https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca", {
  method: "PATCH",
  headers: {
    Authorization: `Bearer ${process.env.AIGENTLY_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "secret": "your-new-orders-api-token"
  }),
});
const answer = await response.json();
if (!response.ok) throw new Error(`${answer.code}: ${answer.detail}`);
console.log(answer);
```

**Python**

```python
# Rotate a tool credential. Tools send the new value from their next request.
# pip install httpx
import os

import httpx

response = httpx.patch(
    "https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca",
    headers={
        "Authorization": f"Bearer {os.environ['AIGENTLY_API_KEY']}",
    },
    json={
        "secret": "your-new-orders-api-token",
    },
)
if response.is_error:
    raise SystemExit(response.text)
print(response.json())
```

**Go**

```go
// Rotate a tool credential. Tools send the new value from their next request.
package main

import (
	"bytes"
	"fmt"
	"io"
	"net/http"
	"os"
)

func main() {
	payload := []byte(`{
  "secret": "your-new-orders-api-token"
}`)
	request, err := http.NewRequest("PATCH", "https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca", bytes.NewReader(payload))
	if err != nil {
		panic(err)
	}
	request.Header.Set("Authorization", "Bearer "+os.Getenv("AIGENTLY_API_KEY"))
	request.Header.Set("Content-Type", "application/json")
	response, err := http.DefaultClient.Do(request)
	if err != nil {
		panic(err)
	}
	defer response.Body.Close()
	body, _ := io.ReadAll(response.Body)
	if response.StatusCode >= 400 {
		fmt.Fprintln(os.Stderr, string(body))
		os.Exit(1)
	}
	fmt.Println(string(body))
}
```

**Java**

```java
// Rotate a tool credential. Tools send the new value from their next request.
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        String body = """
            {
              "secret": "your-new-orders-api-token"
            }
            """;
        HttpRequest request = HttpRequest.newBuilder(URI.create("https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca"))
            .header("Authorization", "Bearer " + System.getenv("AIGENTLY_API_KEY"))
            .header("Content-Type", "application/json")
            .method("PATCH", HttpRequest.BodyPublishers.ofString(body))
            .build();
        // HTTP/1.1: on a plain-http address Java's default asks to upgrade, which not every
        // server allows.
        HttpClient client = HttpClient.newBuilder().version(HttpClient.Version.HTTP_1_1).build();
        HttpResponse<String> response =
            client.send(request, HttpResponse.BodyHandlers.ofString());
        if (response.statusCode() >= 400) {
            System.err.println(response.body());
            System.exit(1);
        }
        System.out.println(response.body());
    }
}
```

**C#**

```csharp
// Rotate a tool credential. Tools send the new value from their next request.
using System.Net.Http.Headers;
using System.Text;

using var client = new HttpClient();
client.DefaultRequestHeaders.Authorization =
    new AuthenticationHeaderValue("Bearer", Environment.GetEnvironmentVariable("AIGENTLY_API_KEY"));
var request = new HttpRequestMessage(HttpMethod.Patch, "https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca")
{
    Content = new StringContent(
        """
        {
          "secret": "your-new-orders-api-token"
        }
        """,
        Encoding.UTF8,
        "application/json"),
};
var response = await client.SendAsync(request);
var body = await response.Content.ReadAsStringAsync();
if (!response.IsSuccessStatusCode)
{
    Console.Error.WriteLine(body);
    return 1;
}
Console.WriteLine(body);
return 0;
```

**PHP**

```php
<?php
// Rotate a tool credential. Tools send the new value from their next request.
$curl = curl_init("https://api.aigently.ai/v1/vault/secrets/2e4a6c8e-0a2c-4e4a-d6c8-e0a2c4e6a8ca");
curl_setopt_array($curl, [
    CURLOPT_CUSTOMREQUEST => "PATCH",
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer " . getenv("AIGENTLY_API_KEY"),
        "Content-Type: application/json",
    ],
    CURLOPT_POSTFIELDS => json_encode([
        "secret" => "your-new-orders-api-token",
    ]),
]);
$body = curl_exec($curl);
if (curl_getinfo($curl, CURLINFO_RESPONSE_CODE) >= 400) {
    fwrite(STDERR, $body . "\n");
    exit(1);
}
echo $body, "\n";
```
