Storages

Rotate the stored credentials of an S3-compatible storage configuration

Replaces only the stored credential: name, discovery settings, provider type, ownership and sharer attribution are untouched — unlike re-registering, which rewrites them. The new credentials are validated against the store before anything persists; on failure the old ones stay live. Rotation cannot revoke the superseded secret (the encrypted handle is the ciphertext) — see the key-rotation runbook for a true revoke. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)

PUT
/v1/storages/configs/{config_id}/credentials/s3

Authorization

BearerAuth
AuthorizationBearer <token>

Security scheme for OpenAPI endpoints. Validates both JWT tokens and API keys.

In: header

Path Parameters

config_id*string
Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Rotate the stored credential of an S3-compatible config (ED-549).

Carries credential fields + expiry only: addressing (bucket, region, endpoint), name, discovery settings, ownership and sharer attribution are untouched by definition — that is what distinguishes rotation from re-registering. Note that rotation cannot revoke the superseded secret: the encrypted handle IS the ciphertext, so a previously leaked handle keeps decrypting until the master EDDYTOR_ENCRYPTION_KEY is rotated (see the key-rotation runbook in deploy/selfhost/HOSTING.md).

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PUT "https://example.com/v1/storages/configs/497f6eca-6276-4993-bfeb-53cbbbba6f08/credentials/s3" \  -H "Content-Type: application/json" \  -d '{    "accessKeyId": "string",    "secretKey": "string"  }'
{  "configId": "46ff6d11-d8b2-40d8-9197-dfa33c61cd6c",  "configName": "string",  "message": "string"}
Empty
Empty
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}
{  "code": "string",  "message": "string",  "request_id": "string",  "details": [    {      "field": "string",      "message": "string"    }  ]}