Skip to content
Proud to collaborate with Microsoft for Startups

connection.rotate.credentials ​

Validates replacement credentials, tests them, updates the existing connection, and marks it active

Rotate or repair credentials for an existing cloud connection.

Public callers use this workflow instead of data.connection.update. The wrapper accepts either the spec-level new_credentials object or the same flattened credential fields used by connection.setup.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-connection
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization that owns the connection
provider_typestringYes—Cloud provider key (aws, gcp, azure, cloudflare, github, route53, lovable, ...)
connection_namestringNo—Human-friendly name for the connection
dialectstringNo—SQL dialect (postgres v1; mysql/etc. later)
hoststringNo—SQL database hostname or IP
portstringNo—SQL database TCP port (default 5432 for postgres)
databasestringNo—SQL database / catalog name
ssl_modestringNo—Postgres sslmode (disable, allow, prefer, require, ...)
usernamestringNo—SQL database username, or the MCP HTTP Basic username
actorstringNo—Authenticated caller (Cognito sub or UUID) initiating the workflow
role_arnstringNo—AWS IAM role ARN to assume
external_refstringNo—External ID for AWS STS:AssumeRole (auto-generated when missing)
regionslistNo—AWS regions the connection should cover
regionstringNo—Default region (Azure / single-region providers)
aws_connection_uuiduuidNo—Existing AWS CloudConnection.uuid (Route53 reuse)
zone_modestringNo—Route53 hosted-zone selection mode
zone_refslistNo—Route53 hosted-zone references
service_account_jsonjsonNo—GCP service-account key (JSON object)
project_refstringNo—GCP project reference; derived from service_account_json when omitted
authorization_codestringNo—iFood distributed authorization code returned after the merchant enters their user code
authorization_code_verifierstringNo—iFood verifier that completes the authorization-code exchange; a secret, not a correlation id
refresh_tokenstringNo—GCP OAuth refresh token (OAuth path)
tenant_refstringNo—Azure AD tenant reference
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id)
auth_modestringNo—Magalu auth mode: api_key, oauth, or object_storage
key_pair_idstringNo—Magalu Object Storage key pair ID
key_pair_secretstringNo—Magalu Object Storage key pair secret
client_refstringNo—Provider application client reference (Azure, iFood, etc.)
client_secretstringNo—Provider application secret (Azure, iFood, etc.)
subscription_refstringNo—Azure subscription reference
app_connection_uuiduuidNo—iFood application connection this merchant authorizes through. When set, the merchant connection stores no application secret of its own
api_tokenstringNo—Bearer/API token credential
api_keystringNo—Generic API key credential
personal_access_tokenstringNo—Account-level personal access / admin token (Wasender)
session_idstringNo—Provider session identifier (Wasender WhatsApp session)
webhook_secretstringNo—Shared secret used to verify inbound provider webhooks
sap_environmentstringNo—SAP data environment: 'sandbox' (Accelerator Hub, default) or 'live'
account_refstringNo—Provider account reference (Cloudflare, etc.)
team_refstringNo—Provider team/organization reference (Vercel)
base_urlstringNo—Self-hosted / OpenAI-compatible provider base URL
azure_endpointstringNo—Azure OpenAI resource endpoint (https://{resource}.openai.azure.com)
api_versionstringNo—Azure OpenAI API version query (e.g. 2024-02-01)
custom_domainstringNo—Custom domain override for self-hosted instances
header_namestringNo—MCP: header to carry the API key (default X-API-Key)
auth_schemestringNo—MCP: Authorization scheme prefix (default Bearer)
resource_urlstringNo—MCP: RFC 9728 protected-resource identifier
authorization_serverstringNo—MCP: issuer of the authorization server backing this resource
authorize_endpointstringNo—MCP: RFC 8414 authorization endpoint
token_endpointstringNo—MCP: RFC 8414 token endpoint
registration_endpointstringNo—MCP: RFC 7591 dynamic client registration endpoint
registered_via_dcrbooleanNo—MCP: client_id was created by dynamic client registration
token_expires_atstringNo—MCP: ISO-8601 expiry of the current access token
scopesjsonNo—MCP: list of OAuth scopes granted for this connection
extra_headersjsonNo—MCP: additional static headers to send on every request
redirect_uristringNo—MCP: primary OAuth callback registered on the DCR client
redirect_urisjsonNo—MCP: all OAuth callbacks registered on the DCR client
organizationstringNo—Organization slug for providers that scope by org
installation_refintegerNo—GitHub App installation reference
access_tokenstringNo—OAuth access token
app_refstringNo—Meta App ID reference (optional; for future token exchange)
app_secretstringNo—Meta App Secret (optional; for future token exchange)
graph_api_versionstringNo—Meta Graph API version (default v21.0)
default_page_refstringNo—Default Meta Page reference for organic publishing
instagram_business_account_refstringNo—Linked Instagram Business Account reference
user_access_tokenstringNo—Long-lived Meta User token for Page/IG discovery
page_access_tokenstringNo—Page access token for the default Meta Page publish target
pagesjsonNo—Cached Meta Pages + IG refs from connection.meta.sync-assets
channel_refstringNo—YouTube channel reference (organic)
channelsjsonNo—Cached YouTube channel inventory from connection.youtube.sync-assets
organization_refstringNo—Organization pin (Deere org id or LinkedIn Community URN)
organizationsjsonNo—Cached org inventory from connection.deere.sync-assets or linkedin-community.sync-assets
ad_account_refstringNo—Ads account reference (meta_ads / linkedin_ads)
ad_accountsjsonNo—Cached Meta Ads ad-account inventory from connection.meta-ads.sync-assets
conversions_api_keystringNo—OpenAI Ads Conversions API key (server-side event sends to bzr.openai.com)
pixel_idstringNo—OpenAI Ads Pixel ID used as the default data source for Conversions API sends
docusign_auth_modestringNo—DocuSign auth mode: user_oauth (default) or org_jwt
docusign_environmentstringNo—DocuSign environment: developer (default) or production
docusign_account_refstringNo—DocuSign account reference (GUID) pin; the userinfo default account when omitted
docusign_user_refstringNo—DocuSign API user reference (GUID) an org_jwt connection impersonates
docusign_rsa_private_keystringNo—RSA private key (PEM) registered on the DocuSign integration key (org_jwt)
accountsjsonNo—Cached DocuSign account inventory from oauth-exchange userinfo
customer_refstringNo—Google Ads customer / account reference
developer_tokenstringNo—Google Ads API developer token
accountjsonNo—Authenticated X user {id, username, name, profile_image_url} from oauth-exchange
api_secretstringNo—Provider API secret
bot_tokenstringNo—Slack bot token (xoxb-...)
signing_secretstringNo—Slack request signing secret
enterprise_refstringNo—Slack enterprise/team grid reference
bot_user_refstringNo—Slack bot user reference
access_key_refstringNo—Alibaba Cloud access key reference
access_key_secretstringNo—Alibaba Cloud access key secret
endpoint_urlstringNo—S3-compatible endpoint URL (Neon branch storage endpoint)
s3_endpointstringNo—Alias for endpoint_url (Neon Object Storage)
branch_refstringNo—Neon branch reference (label only for neon_storage)
auth_methodstringNo—Sentry auth method
tokenstringNo—Sentry auth token
organization_slugstringNo—Sentry organization slug
project_slugstringNo—Sentry project slug
expires_atstringNo—ISO-8601 expiry of the current OAuth access_token
scopestringNo—OAuth scope string granted by the provider
company_refstringNo—Provider-side account/company reference (Bling)
kubernetes_auth_modestringNo—Kubernetes auth mode: static, incluster_service_account, gke_delegated, or eks_delegated
kubernetes_provider_connection_uuiduuidNo—Same-organization GCP/AWS connection used for delegated token minting
kubernetes_cluster_locationstringNo—Cluster region or location used by delegated authentication
kubernetes_cluster_namestringNo—Provider cluster name used by delegated authentication
kubeconfigstringNo—Full kubeconfig YAML; parsed server-side into the three discrete fields
api_serverstringNo—Kubernetes API server URL (https://...); overrides parsed kubeconfig server when set
bearer_tokenstringNo—ServiceAccount or static bearer token
ca_certificatestringNo—Cluster CA bundle (PEM)
namespace_defaultstringNo—Default Kubernetes namespace for ops that don't carry one
connection_uuiduuidYes—UUID of the connection whose credentials should be rotated
new_credentialsjsonNo—Replacement credential payload; flattened fields are also accepted
candidate_credentialsjsonNo—Alias accepted by repair flows for replacement credentials
dry_runbooleanNo—Validate and test without mutating the stored connection
rotation_strategystringNo—Caller supplied rotation mode or policy key
reconcile_dependentsbooleanNo—Whether dependent resources should be reconciled after rotation
idempotency_keystringNo—Caller supplied idempotency key for safe retries

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Organization that owns the connection
provider_typestringYes—Cloud provider key (aws, gcp, azure, cloudflare, github, route53, lovable, ...)
connection_namestringNo—Human-friendly name for the connection
dialectstringNo—SQL dialect (postgres v1; mysql/etc. later)
hoststringNo—SQL database hostname or IP
portstringNo—SQL database TCP port (default 5432 for postgres)
databasestringNo—SQL database / catalog name
ssl_modestringNo—Postgres sslmode (disable, allow, prefer, require, ...)
actorstringNo—Authenticated caller (Cognito sub or UUID) initiating the workflow
role_arnstringNo—AWS IAM role ARN to assume
regionslistNo—AWS regions the connection should cover
regionstringNo—Default region (Azure / single-region providers)
aws_connection_uuiduuidNo—Existing AWS CloudConnection.uuid (Route53 reuse)
zone_modestringNo—Route53 hosted-zone selection mode
zone_refslistNo—Route53 hosted-zone references
project_refstringNo—GCP project reference; derived from service_account_json when omitted
tenant_refstringNo—Azure AD tenant reference
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id)
auth_modestringNo—Magalu auth mode: api_key, oauth, or object_storage
client_refstringNo—Provider application client reference (Azure, iFood, etc.)
subscription_refstringNo—Azure subscription reference
app_connection_uuiduuidNo—iFood application connection this merchant authorizes through. When set, the merchant connection stores no application secret of its own
session_idstringNo—Provider session identifier (Wasender WhatsApp session)
sap_environmentstringNo—SAP data environment: 'sandbox' (Accelerator Hub, default) or 'live'
account_refstringNo—Provider account reference (Cloudflare, etc.)
team_refstringNo—Provider team/organization reference (Vercel)
base_urlstringNo—Self-hosted / OpenAI-compatible provider base URL
azure_endpointstringNo—Azure OpenAI resource endpoint (https://{resource}.openai.azure.com)
api_versionstringNo—Azure OpenAI API version query (e.g. 2024-02-01)
custom_domainstringNo—Custom domain override for self-hosted instances
header_namestringNo—MCP: header to carry the API key (default X-API-Key)
auth_schemestringNo—MCP: Authorization scheme prefix (default Bearer)
resource_urlstringNo—MCP: RFC 9728 protected-resource identifier
authorization_serverstringNo—MCP: issuer of the authorization server backing this resource
authorize_endpointstringNo—MCP: RFC 8414 authorization endpoint
token_endpointstringNo—MCP: RFC 8414 token endpoint
registration_endpointstringNo—MCP: RFC 7591 dynamic client registration endpoint
registered_via_dcrbooleanNo—MCP: client_id was created by dynamic client registration
token_expires_atstringNo—MCP: ISO-8601 expiry of the current access token
scopesjsonNo—MCP: list of OAuth scopes granted for this connection
extra_headersjsonNo—MCP: additional static headers to send on every request
redirect_uristringNo—MCP: primary OAuth callback registered on the DCR client
redirect_urisjsonNo—MCP: all OAuth callbacks registered on the DCR client
organizationstringNo—Organization slug for providers that scope by org
installation_refintegerNo—GitHub App installation reference
app_refstringNo—Meta App ID reference (optional; for future token exchange)
app_secretstringNo—Meta App Secret (optional; for future token exchange)
graph_api_versionstringNo—Meta Graph API version (default v21.0)
default_page_refstringNo—Default Meta Page reference for organic publishing
instagram_business_account_refstringNo—Linked Instagram Business Account reference
user_access_tokenstringNo—Long-lived Meta User token for Page/IG discovery
page_access_tokenstringNo—Page access token for the default Meta Page publish target
pagesjsonNo—Cached Meta Pages + IG refs from connection.meta.sync-assets
channel_refstringNo—YouTube channel reference (organic)
channelsjsonNo—Cached YouTube channel inventory from connection.youtube.sync-assets
organization_refstringNo—Organization pin (Deere org id or LinkedIn Community URN)
organizationsjsonNo—Cached org inventory from connection.deere.sync-assets or linkedin-community.sync-assets
ad_account_refstringNo—Ads account reference (meta_ads / linkedin_ads)
ad_accountsjsonNo—Cached Meta Ads ad-account inventory from connection.meta-ads.sync-assets
pixel_idstringNo—OpenAI Ads Pixel ID used as the default data source for Conversions API sends
docusign_auth_modestringNo—DocuSign auth mode: user_oauth (default) or org_jwt
docusign_environmentstringNo—DocuSign environment: developer (default) or production
docusign_account_refstringNo—DocuSign account reference (GUID) pin; the userinfo default account when omitted
docusign_user_refstringNo—DocuSign API user reference (GUID) an org_jwt connection impersonates
docusign_rsa_private_keystringNo—RSA private key (PEM) registered on the DocuSign integration key (org_jwt)
accountsjsonNo—Cached DocuSign account inventory from oauth-exchange userinfo
customer_refstringNo—Google Ads customer / account reference
accountjsonNo—Authenticated X user {id, username, name, profile_image_url} from oauth-exchange
enterprise_refstringNo—Slack enterprise/team grid reference
bot_user_refstringNo—Slack bot user reference
endpoint_urlstringNo—S3-compatible endpoint URL (Neon branch storage endpoint)
s3_endpointstringNo—Alias for endpoint_url (Neon Object Storage)
branch_refstringNo—Neon branch reference (label only for neon_storage)
auth_methodstringNo—Sentry auth method
organization_slugstringNo—Sentry organization slug
project_slugstringNo—Sentry project slug
expires_atstringNo—ISO-8601 expiry of the current OAuth access_token
scopestringNo—OAuth scope string granted by the provider
company_refstringNo—Provider-side account/company reference (Bling)
kubernetes_auth_modestringNo—Kubernetes auth mode: static, incluster_service_account, gke_delegated, or eks_delegated
kubernetes_provider_connection_uuiduuidNo—Same-organization GCP/AWS connection used for delegated token minting
kubernetes_cluster_locationstringNo—Cluster region or location used by delegated authentication
kubernetes_cluster_namestringNo—Provider cluster name used by delegated authentication
api_serverstringNo—Kubernetes API server URL (https://...); overrides parsed kubeconfig server when set
ca_certificatestringNo—Cluster CA bundle (PEM)
namespace_defaultstringNo—Default Kubernetes namespace for ops that don't carry one
connection_uuiduuidNo—UUID of the connection whose credentials were rotated
dry_runbooleanNo—True when the workflow skipped mutation
rotation_strategystringNo—Caller supplied rotation mode or policy key
reconcile_dependentsbooleanNo—Caller requested dependent reconciliation
idempotency_keystringNo—Caller supplied idempotency key
initiated_atstringNo—ISO-8601 timestamp when rotation began
initiated_bystringNo—Actor that initiated rotation
validation_passedbooleanNo—True after credential validation
validated_atstringNo—ISO-8601 timestamp of credential validation
test_passedbooleanNo—True after replacement credentials tested successfully
test_resultjsonNo—Provider connectivity test result
account_infojsonNo—Provider account metadata returned by the test
tested_atstringNo—ISO-8601 timestamp of connectivity test
updated_fieldslistNo—Fields changed by data.connection.update
updated_atstringNo—ISO-8601 timestamp of credential update
new_statusstringNo—Connection status after status update
last_validated_atstringNo—ISO-8601 timestamp of last successful validation
validation_countintegerNo—Total validations performed on the row
statusstringNo—Workflow-level status
summaryjsonNo—Workflow summary
warningslistNo—Non-fatal warnings
completed_atstringNo—ISO-8601 timestamp when rotation completed
failure_reasonstringNo—Failure reason on the failed branch
failure_typestringNo—Failure category
failed_actionstringNo—Action method that raised
failed_at_statestringNo—State the workflow was in when it failed
failed_atstringNo—ISO-8601 timestamp of failure
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name
failed_layerstringNo—Engine-stamped layer index
failed_stepstringNo—Engine-stamped step name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—rotateCredential rotation request received
completedNoYesYes—Credentials rotated
failedNoYesNo—Credential rotation failed

State Diagram ​

Transitions ​

FromActionToDescription
initiatedrotatecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "connection.rotate.credentials",
  "initial_data": {
    "organization_uuid": "value",
    "provider_type": "value",
    "connection_uuid": "value"
  }
}