Skip to content
Proud to collaborate with Microsoft for Startups

appdata.credential.rotate ​

Rotate a direct-connection credential's password

Replace a credential's password. Existing sessions keep running until they end.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-appdata
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID
identity_app_uuiduuidYes—Identity app the credential reads; must own an appdata namespace in this organization
request_idstringNo—Caller request id for audit correlation
actorstringNo——
credential_uuiduuidYes——

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
identity_app_uuiduuidYes——
credential_uuiduuidNo——
role_namestringNo—The Postgres login role; joins to pg_stat_activity.usename
labelstringNo——
connection_limitintegerNo——
valid_untilstringNo——
created_atstringNo——
last_rotated_atstringNo——
revoked_atstringNo——
hoststringNo——
portstringNo——
databasestringNo——
sslmodestringNo—'require' until the identity-aware gateway offers verify-full
dsnstringNo—Connection string with the password redacted; pair it with token
tokenstringNo—The password. Returned exactly once, never stored; this is the only output the secret contract reveals
failure_reasonstringNo—Engine-stamped failure reason
failed_at_statestringNo—State when the workflow failed
failed_stepstringNo—Failed DAG step name
failed_layerintegerNo—Failed DAG layer index
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completeRotate credential
completedNoYesYes—Credential rotated
failedNoYesNo—Rotate failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
rotatedSUCCESSRotate a direct-connection credential's passwordcredential_uuid
failedFAILUREAppdata workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "appdata.credential.rotate",
  "initial_data": {
    "organization_uuid": "value",
    "identity_app_uuid": "value",
    "credential_uuid": "value"
  }
}