Rotate the stored credentials of an S3-compatible storage configuration
Replaces only the stored credential: name, discovery settings, provider type, ownership and sharer attribution are untouched — unlike re-registering, which rewrites them. The new credentials are validated against the store before anything persists; on failure the old ones stay live. Rotation cannot revoke the superseded secret (the encrypted handle is the ciphertext) — see the key-rotation runbook for a true revoke. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)
Authorization
BearerAuth Security scheme for OpenAPI endpoints. Validates both JWT tokens and API keys.
In: header
Path Parameters
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Rotate the stored credential of an S3-compatible config (ED-549).
Carries credential fields + expiry only: addressing (bucket, region,
endpoint), name, discovery settings, ownership and sharer attribution are
untouched by definition — that is what distinguishes rotation from
re-registering. Note that rotation cannot revoke the superseded secret:
the encrypted handle IS the ciphertext, so a previously leaked handle
keeps decrypting until the master EDDYTOR_ENCRYPTION_KEY is rotated
(see the key-rotation runbook in deploy/selfhost/HOSTING.md).
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PUT "https://example.com/v1/storages/configs/497f6eca-6276-4993-bfeb-53cbbbba6f08/credentials/s3" \ -H "Content-Type: application/json" \ -d '{ "accessKeyId": "string", "secretKey": "string" }'{ "configId": "46ff6d11-d8b2-40d8-9197-dfa33c61cd6c", "configName": "string", "message": "string"}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}Delete a storage configuration
Soft-deletes the storage configuration from the database and notifies the engine to clean up DataFusion registrations. All tables associated with this configuration will become inaccessible. This action cannot be undone. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)
Rotate the stored credentials of an Azure storage configuration
Exactly one auth mode (access key, SAS token, service principal, or managed identity); account, container and endpoint flags are preserved. Delegated-OAuth configs hold no stored secret and answer 422 — update access there through the provider link flow. **Required scope:** `storage:configure` (+ `storage_configs:share` for workspace-shared configs)