> ## Documentation Index
> Fetch the complete documentation index at: https://developer.communicate.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Rename or narrow an owned active credential

> Use an explicit credentials:write account bearer grant or a live email-verified application session, plus the current account password as fresh identity proof. Cookie writes require a trusted Origin. Machine callers cannot issue scopes beyond their own grant or outlive it. Creation and rotation return the secret once; metadata never includes it. Scope and expiry can only be narrowed. Issued credentials expire within 24 hours and no later than their issuer session; session revocation invalidates them.



## OpenAPI

````yaml https://app.communicate.so/api/v1/openapi/mintlify.json patch /account-credentials/{credentialId}
openapi: 3.1.0
info:
  title: Communicate Public REST API
  version: 1.1.0
  summary: >-
    Scoped agent chat, account credential lifecycle and workspace bootstrap
    operations.
  description: >-
    Canonical external schema for implemented REST operations. Account
    credentials and application sessions authorize the documented account and
    workspace operations separately from workspace keys. Exchange a workspace
    API-key client ID and secret for a short-lived OAuth access token, or use
    the `ck_` key directly for backward compatibility. `requestId` is optional
    but, when supplied, becomes the idempotency key for retries of the same chat
    input.
servers:
  - url: https://app.communicate.so/api/v1
    description: Canonical external base URL served through the Next.js /api/v1 rewrite.
security:
  - oauth2: []
  - bearerAuth: []
paths:
  /account-credentials/{credentialId}:
    patch:
      tags:
        - Account credentials
      summary: Rename or narrow an owned active credential
      description: >-
        Use an explicit credentials:write account bearer grant or a live
        email-verified application session, plus the current account password as
        fresh identity proof. Cookie writes require a trusted Origin. Machine
        callers cannot issue scopes beyond their own grant or outlive it.
        Creation and rotation return the secret once; metadata never includes
        it. Scope and expiry can only be narrowed. Issued credentials expire
        within 24 hours and no later than their issuer session; session
        revocation invalidates them.
      operationId: editAccountCredential
      parameters:
        - name: credentialId
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: Origin
          in: header
          required: false
          description: >-
            Required for cookie authentication: an exact trusted application
            origin configured by the server. Bearer requests do not require
            Origin.
          schema:
            type: string
            format: uri
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccountCredentialEdit'
      responses:
        '200':
          description: Rename or narrow an owned active credential
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountCredentialMetadata'
          headers:
            Cache-Control:
              schema:
                type: string
                const: no-store
        '400':
          description: Invalid request body or pagination.
        '401':
          description: >-
            Session or credential missing, invalid, expired or revoked; fresh
            password proof failed when required.
        '403':
          description: >-
            Email verification, trusted origin or required account scope is
            missing.
        '404':
          description: Credential not found in the authenticated user account.
        '409':
          description: >-
            Credential is inactive, already rotated, or requested scopes or
            expiry exceed its existing authority.
        '429':
          description: Per-user list or password proof rate limit exceeded.
        '500':
          description: Unexpected server failure.
        '503':
          description: Identity service or freshly issued session unavailable.
      security:
        - accountBearer: []
        - accountSession: []
        - localAccountSession: []
components:
  schemas:
    AccountCredentialEdit:
      type: object
      properties:
        password:
          writeOnly: true
          format: password
          type: string
          minLength: 1
          maxLength: 1024
        name:
          type: string
          minLength: 5
          maxLength: 300
        scopes:
          minItems: 1
          maxItems: 20
          type: array
          items:
            type: string
            enum:
              - workspaces:read
              - workspaces:write
              - workspaces:manage
              - members:read
              - members:write
              - teams:read
              - teams:write
              - invites:accept
              - agents:read
              - agents:write
              - sources:read
              - sources:write
              - learnings:read
              - learnings:write
              - grill:read
              - grill:write
              - notifications:read
              - notifications:write
              - credentials:read
              - credentials:write
        expiresAt:
          description: Future expiry no later than the existing credential expiry.
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
      required:
        - password
      additionalProperties: false
      description: >-
        Provide at least one of name, scopes or expiresAt, plus password. Scopes
        must be a subset of the current scopes; expiry must be future and no
        later than the current expiry.
    AccountCredentialMetadata:
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        name:
          type: string
          minLength: 5
          maxLength: 300
        prefix:
          type: string
        scopes:
          minItems: 1
          maxItems: 20
          type: array
          items:
            type: string
            enum:
              - workspaces:read
              - workspaces:write
              - workspaces:manage
              - members:read
              - members:write
              - teams:read
              - teams:write
              - invites:accept
              - agents:read
              - agents:write
              - sources:read
              - sources:write
              - learnings:read
              - learnings:write
              - grill:read
              - grill:write
              - notifications:read
              - notifications:write
              - credentials:read
              - credentials:write
        expiresAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        audience:
          type: string
          const: https://app.communicate.so/api/v1
        revokedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            - type: 'null'
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        rotatedFromId:
          anyOf:
            - type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
            - type: 'null'
      required:
        - id
        - name
        - prefix
        - scopes
        - expiresAt
        - audience
        - revokedAt
        - createdAt
        - rotatedFromId
      additionalProperties: false
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client-credentials tokens bounded by the source API key scope
        ceiling.
      flows:
        clientCredentials:
          tokenUrl: https://app.communicate.so/api/v1/oauth/token
          scopes:
            agents:read: List agents in the authenticated workspace.
            chat:write: Create chat turns with an agent in the authenticated workspace.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: Workspace API key token with the `ck_` prefix.
    accountBearer:
      type: http
      scheme: bearer
      bearerFormat: Account credential
      description: >-
        Opaque user-bound `ca_` account credential. Each request checks live
        account scopes, verified email, expiry, revocation and the issuer
        session. Not a workspace `ck_` key or OAuth access token.
    accountSession:
      type: apiKey
      in: cookie
      name: __Secure-better-auth.session_token
      description: >-
        Signed Better Auth session cookie for an HTTPS application origin.
        Credential management additionally requires verified email and fresh
        password proof on writes.
    localAccountSession:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: >-
        Signed session cookie used when the configured application auth origin
        is HTTP, such as local development.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.