Update Credential
api/beta/vaults/credentials/update
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/vaults/credentials/update Changed · +54 / -65 lines
# Update Credential ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200) ## Update Credential ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
---- -title: Update Credential -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/update ---- +# Update Credential -## Update Credential +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}` -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}` - Update Credential -### Path Parameters +## Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +## Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +## Body parameters - `auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams` Updated authentication details for a credential. - - `BetaManagedAgentsMCPOAuthUpdateParams object { type, access_token, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthUpdateParams object` Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable. - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `access_token: optional string or null` Updated OAuth access token. + minLength: 1, maxLength: 8192 + - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null` Parameters for updating OAuth refresh token configuration.
Updated OAuth refresh token. + minLength: 1, maxLength: 4096 + - `scope: optional string or null` Updated OAuth scope for the refresh request. + maxLength: 8192 + - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` Updated HTTP Basic authentication parameters for the token endpoint. - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` + - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` + minLength: 1, maxLength: 512 + - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` + Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsStaticBearerUpdateParams object { type, token }` + minLength: 1, maxLength: 512 + - `BetaManagedAgentsStaticBearerUpdateParams object` + Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable. - `type: "static_bearer"` - - `"static_bearer"` - - `token: optional string or null` Updated static bearer token value. - - `BetaManagedAgentsEnvironmentVariableUpdateParams object { type, injection_location, networking, secret_value }` + minLength: 1, maxLength: 8192 + - `BetaManagedAgentsEnvironmentVariableUpdateParams object` + Parameters for updating an environment variable credential. `secret_name` is immutable. - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams` Updated injection location.
Updated networking scope. Full replacement. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - Substitute the secret only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_value: optional string or null` Updated secret value. + minLength: 1, maxLength: 4096 + - `display_name: optional string or null` Updated human-readable name for the credential. 1-255 characters. + minLength: 1, maxLength: 255 + - `metadata: optional map[string] or null` Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved. -### Returns +## Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - Environment variable credential details. The secret value is never returned. - `injection_location: BetaManagedAgentsInjectionLocationResponse`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - The secret is substituted only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable.
- `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +### Response (200) ```json {