Update credential
PUT
https://app.sulus.ai/api/tools/credentials/{id}
Update an owned credential (auth type is immutable)
Authentication
Send a bearer token created on your dashboard's Developer page:
Authorization: Bearer <YOUR_API_KEY>
Path parameters
id
string
Required
The credential's public id.
Validation:
the credential's public id, owned by the authenticated userRequest body
provider
string
Required
Credential kind. Defaults to custom-credential when omitted.
Validation:
required|string|in:custom-credential,webhookname
string
Optional
Nullable
Display name.
Validation:
nullable|string|max:40authenticationPlan
object
Required
The auth configuration — shape depends on type.
Validation:
required|arrayauthenticationPlan.type
string
Required
Immutable after creation — update rejects a differing type.
Validation:
required|string|in:bearer,oauth2,hmacauthenticationPlan.token
string
Optional
Nullable
Bearer token value.
Validation:
required when type=bearerauthenticationPlan.headerName
string
Optional
Nullable
bearer only — defaults to Authorization.
Validation:
nullable|stringauthenticationPlan.bearerPrefixEnabled
boolean
Optional
Nullable
bearer only.
Validation:
nullable|booleanauthenticationPlan.url
string
Optional
Nullable
OAuth2 token URL.
Validation:
required when type=oauth2authenticationPlan.clientId
string
Optional
Nullable
Validation:
required when type=oauth2authenticationPlan.clientSecret
string
Optional
Nullable
Validation:
required when type=oauth2authenticationPlan.scope
string
Optional
Nullable
oauth2 only.
Validation:
nullable|stringauthenticationPlan.secretKey
string
Optional
Nullable
Validation:
required when type=hmacauthenticationPlan.algorithm
string
Optional
Nullable
Validation:
required when type=hmacauthenticationPlan.signatureHeader
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.signaturePrefix
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.timestampHeader
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.messageIdHeader
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.includeTimestamp
boolean
Optional
Nullable
hmac only.
Validation:
nullable|booleanauthenticationPlan.payloadFormat
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.signatureEncoding
string
Optional
Nullable
hmac only.
Validation:
nullable|stringauthenticationPlan.secretIsBase64
boolean
Optional
Nullable
hmac only.
Validation:
nullable|booleanencryptionPlan
object
Optional
Nullable
Optional public-key encryption for the stored secret.
Validation:
nullable|arrayencryptionPlan.publicKey
string
Optional
Nullable
Requests are encrypted with this key before being sent.
Validation:
nullable — PEM-formatted public keyErrors
| Status | Meaning | Body |
|---|---|---|
401 |
No authenticated user | {"success":false,"message":"Unauthenticated."} |
404 |
Credential not found, or not owned by the caller | {"success":false,"message":"Credential not found."} |
422 |
Auth type differs from the stored credential | {"success":false,"message":"Auth type cannot be changed (credential is bearer). Create a new credential instead."} |
422 |
Missing per-type required fields | {"success":false,"message":"Token is required."} |
502 |
Live credential update failed | {"success":false,"message":"<cleaned upstream error>"} |
422 |
Validation failed | {"message":"…","errors":{"field":["…"]}} |
403 |
Feature tools not enabled for the account |
Notes
- The credential's public id never changes across an update, so tools referencing it stay valid.
- Secrets are re-entered on every update — the platform never returns a previously stored secret for display.
curl --request PUT \
--url https://app.sulus.ai/api/tools/credentials/{id} \
--header 'Authorization: Bearer <YOUR_API_KEY>' \
--header 'Content-Type: application/json' \
--data '{
"provider": "custom-credential",
"name": "Orders API (v2)",
"authenticationPlan": {
"type": "bearer",
"token": "sk_live_51Hyyyyyyyyyyyyyyyyyyyyyyyy",
"bearerPrefixEnabled": true
}
}'
import requests
url = "https://app.sulus.ai/api/tools/credentials/{id}"
headers = {"Authorization": "Bearer <YOUR_API_KEY>"}
payload = {
"provider": "custom-credential",
"name": "Orders API (v2)",
"authenticationPlan": {
"type": "bearer",
"token": "sk_live_51Hyyyyyyyyyyyyyyyyyyyyyyyy",
"bearerPrefixEnabled": true
}
}
response = requests.put(url, json=payload, headers=headers)
print(response.json())
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
url := "https://app.sulus.ai/api/tools/credentials/{id}"
payload := strings.NewReader(`{
"provider": "custom-credential",
"name": "Orders API (v2)",
"authenticationPlan": {
"type": "bearer",
"token": "sk_live_51Hyyyyyyyyyyyyyyyyyyyyyyyy",
"bearerPrefixEnabled": true
}
}`)
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <YOUR_API_KEY>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}
Response
200
{
"success": true,
"data": {
"id": "3f9c2a10-6b4e-4a2d-9f0a-1c2d3e4f5a6b",
"provider": "custom-credential",
"name": "Orders API (v2)",
"auth_type": "bearer",
"encryption_enabled": false,
"status": "active"
}
}
Response — PUT
/tools/credentials/{id}
200
{
"success": true,
"data": {
"id": "3f9c2a10-6b4e-4a2d-9f0a-1c2d3e4f5a6b",
"provider": "custom-credential",
"name": "Orders API (v2)",
"auth_type": "bearer",
"encryption_enabled": false,
"status": "active"
}
}