Skip to main content
PATCH
Update credential

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id_or_name
string
required

Credential ID or name

Body

application/json

Request to update an existing credential

name
string

New name for the credential

Example:

"my-updated-login"

remove_value_keys
string[]

Field names to remove from the credential's stored values. Removals are applied before values are merged, so a key present in both is kept with its new value.

Example:
sso_provider
string | null

If set, indicates this credential should be used with the specified SSO provider. Set to empty string or null to remove.

Example:

"google"

totp_secret
string

Base32-encoded TOTP secret for generating one-time passwords. Spaces and formatting are automatically normalized. Set to empty string to remove.

Example:

"JBSWY3DPEHPK3PXP"

values
object

Field name to value mapping. Values are merged with existing values (new keys added, existing keys overwritten).

Example:

Response

Credential updated successfully

A stored credential for automatic re-authentication

created_at
string<date-time>
required

When the credential was created

Example:

"2025-01-15T10:30:00Z"

domain
string
required

Target domain this credential is for

Example:

"netflix.com"

id
string
required

Unique identifier for the credential

Example:

"cred_abc123xyz"

name
string
required

Unique name for the credential within the project

Example:

"my-netflix-login"

updated_at
string<date-time>
required

When the credential was last updated

Example:

"2025-01-15T10:30:00Z"

has_totp_secret
boolean

Whether this credential has a TOTP secret configured for automatic 2FA

Example:

false

has_values
boolean

Whether this credential has stored values (email, password, etc.)

Example:

true

sso_provider
string | null

If set, indicates this credential should be used with the specified SSO provider (e.g., google, github, microsoft). When the target site has a matching SSO button, it will be clicked first before filling credential values on the identity provider's login page.

Example:

"google"

totp_code
string

Current 6-digit TOTP code. Only included in create/update responses when totp_secret was just set.

Example:

"847291"

totp_code_expires_at
string<date-time>

When the totp_code expires. Only included when totp_code is present.

Example:

"2025-01-15T10:30:30Z"

value_keys
string[]

The field names stored in this credential's values (e.g., username, password). Values themselves are never returned. Included on single-credential responses (create, get by id or name, update); omitted from list responses.

Example: