Skip to main content
POST
Rotate retailer client secret

Authorizations

X-API-Key
string
header
required

Path Parameters

organization_id
string<shortuuid>
required

Organization ID.

Required string length: 22
Pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
client_id
string<shortuuid>
required

ID of the retailer client.

Required string length: 22
Pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$

Response

OK

The client after rotation, with its new secret. The previous secret stops working immediately.

id
string<shortuuid>
required

URL-safe 22-character shortuuid encoding of the row's UUID primary key. Stable across the row's lifetime; suitable for sharing in URLs, log lines, and external SDK clients. Accepted on input as either the shortuuid form or the canonical UUID form (xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx).

Required string length: 22
Pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
name
string
required

Human-readable label for this credential.

client_id
string
required

Public client identifier. Opaque, stable, safe to log.

sector_identifier
string
required

Canonical (lower-cased) host that scopes the pairwise subject identifiers issued to this client. Belongs to one organization.

backfill_lookback_days
integer
required

How many days back the retailer declares it will backfill purchases on first link.

submission_cadence_hours
integer
required

How often, in hours, the retailer declares it will submit purchases.

is_enabled
boolean
required

False while the client's credentials are rejected.

secret_prefix
string
required

Leading characters of the current secret, for identification only. Never sufficient to authenticate.

created
string
required

ISO 8601 timestamp the client was registered.

client_secret
string
required

The client secret. Returned only in this response; it cannot be retrieved again, only rotated.

retailer_id
string<shortuuid> | null

URL-safe 22-character shortuuid encoding of the row's UUID primary key. Stable across the row's lifetime; suitable for sharing in URLs, log lines, and external SDK clients. Accepted on input as either the shortuuid form or the canonical UUID form (xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx).

Required string length: 22
Pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
secret_rotated_at
string | null

ISO 8601 timestamp the secret was last rotated, or null if the original is still current.

last_used
string | null

ISO 8601 timestamp of the last successful authentication, or null if never used.