Rotate the stored credentials of an Azure storage configuration
Exactly one auth mode (access key, SAS token, service principal, or managed identity); account, container and endpoint flags are preserved. Delegated-OAuth configs hold no stored secret and answer 422 — update access there through the provider link flow. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)
Authorization
BearerAuth Security scheme for OpenAPI endpoints. Validates both JWT tokens and API keys.
In: header
Path Parameters
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Rotate the stored credential of an Azure config (ED-549). Exactly one auth
mode: access key, SAS token, service principal (all three SP fields), or
managed identity. Account name, container and the fabric-endpoint flag are
preserved from the existing configuration. See
[RotateS3CredentialsRequest] for what rotation deliberately cannot do.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PUT "https://example.com/v1/storages/configs/497f6eca-6276-4993-bfeb-53cbbbba6f08/credentials/az" \ -H "Content-Type: application/json" \ -d '{}'{ "configId": "46ff6d11-d8b2-40d8-9197-dfa33c61cd6c", "configName": "string", "message": "string"}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}Rotate the stored credentials of an S3-compatible storage configuration
Replaces only the stored credential: name, discovery settings, provider type, ownership and sharer attribution are untouched — unlike re-registering, which rewrites them. The new credentials are validated against the store before anything persists; on failure the old ones stay live. Rotation cannot revoke the superseded secret (the encrypted handle is the ciphertext) — see the key-rotation runbook for a true revoke. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)
Rotate the stored credentials of a Google Cloud Storage configuration
The bucket is preserved; only the service-account key (+ optional expiry) moves. Delegated-OAuth configs answer 422 — see the provider link flow. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)