Skip to main content

Update an auth profile

PUT 

/v1/auth-profiles/:auth_profile_id

Change an auth profile's client_id, client_secret, token_endpoint_url, requested_scope or profile_type. Requires the connector:auth-profiles:update scope and an Idempotency-Key header. data.id must equal the auth_profile_id of the path.

Send only the attributes to change; at least one is required (otherwise 422 MISSING_ANY_OF). Sent values must not be empty, and a new token_endpoint_url must be an https:// URL. Sending client_secret rotates the credential.

Effect on webhooks. After a successful update, every webhook bound to this profile goes back to PENDING_VERIFICATION and receives a new webhook.verification event, authenticated with a token obtained with the new settings. Business events are not delivered to those webhooks until the handshake is acknowledged with 2xx. The cached access token of the previous version is not reused. To rotate a client secret without losing events, make your token endpoint accept both the old and the new secret during the change.

Request​

Responses​

Accepted. The update is applied and bound webhooks are in PENDING_VERIFICATION until their new handshake succeeds.