Update an auth profile
PUT/v1/auth-profiles/:auth_profile_id
Change an auth profile's client_id, client_secret, token_endpoint_url,
requested_scope or profile_type. Requires the connector:auth-profiles:update
scope and an Idempotency-Key header. data.id must equal the auth_profile_id of the
path.
Send only the attributes to change; at least one is required (otherwise
422 MISSING_ANY_OF). Sent values must not be empty, and a new token_endpoint_url
must be an https:// URL. Sending client_secret rotates the credential.
Effect on webhooks. After a successful update, every webhook bound to this profile
goes back to PENDING_VERIFICATION and receives a new webhook.verification event,
authenticated with a token obtained with the new settings. Business events are not
delivered to those webhooks until the handshake is acknowledged with 2xx. The cached
access token of the previous version is not reused. To rotate a client secret without
losing events, make your token endpoint accept both the old and the new secret during
the change.
Request
Responses
- 202
- 400
- 401
- 403
- 404
- 409
- 422
- 429
- 503
Accepted. The update is applied and bound webhooks are in PENDING_VERIFICATION
until their new handshake succeeds.
data.id does not match the path, auth_profile_id is not a UUID, a sent value is
empty or invalid, the update changes nothing, or the Idempotency-Key header is
missing.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The request conflicts with an earlier request or with the current state of the target:
an Idempotency-Key reused with a different body (IDEMPOTENCY_CONFLICT), a request with
the same key still in progress (IDEMPOTENCY_PENDING), or a target resource in a state
that does not allow the request (STATE_CONFLICT).
The request is well-formed JSON but cannot be processed: the body does not match the
expected shape (a missing or unknown member, a wrong type, or a wrong data.type), or it
breaks a business or cross-field rule. Correct the request before retrying.
The request was refused because a rate limit was reached (code RATE_LIMITED). No
Retry-After header is sent; retry with exponential backoff.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.