> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate retailer client secret

> Issue a new secret for a retailer client. The previous secret stops working immediately and there is no overlap window. The new secret is returned in this response only. Requires MANAGE_RETAILER_CLIENTS permission.



## OpenAPI

````yaml /openapi/openapi-account.json post /account/api/v1/organizations/{organization_id}/retailer-clients/{client_id}/rotate-secret
openapi: 3.1.0
info:
  title: Account API
  version: 1.0.0
  description: >
    Authenticate and manage users, organizations, and API keys.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Account
    description: Authenticate and introspect the current user and API key.
  - name: Organizations
    description: Create and manage organizations (businesses).
  - name: Members
    description: Invite, update, and remove organization members.
  - name: API Keys
    description: Create, list, and revoke API keys.
  - name: Preferences
    description: >-
      Create, list, update, and delete the authenticated user's stored trait
      preferences (allergens, dietary stances, certifications, sensitivities).
  - name: Scan History
    description: >-
      Read the current visitor's scan history (authenticated or
      anonymous/session-based) and capture anonymous resolver scans.
  - name: Enrollment Codes
    description: >-
      Mint, list, view, and revoke single-use manual enrollment codes for
      linking a retailer to your account (C-4793).
  - name: Retailer Clients
    description: >-
      Register, list, rotate the secret of, and enable or disable the retailer
      API clients of an organization (C-5848).
  - name: Retailer Links
    description: >-
      List, view, unlink, and delete purchase history for the retailers linked
      to your account (C-4794).
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /account/api/v1/organizations/{organization_id}/retailer-clients/{client_id}/rotate-secret:
    post:
      tags:
        - Retailer Clients
      summary: Rotate retailer client secret
      description: >-
        Issue a new secret for a retailer client. The previous secret stops
        working immediately and there is no overlap window. The new secret is
        returned in this response only. Requires MANAGE_RETAILER_CLIENTS
        permission.
      operationId: apps_accounts_api_retailer_clients_rotate_retailer_client_secret
      parameters:
        - in: path
          name: organization_id
          schema:
            description: Organization ID.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Organization Id
            type: string
          required: true
          description: Organization ID.
        - in: path
          name: client_id
          schema:
            description: ID of the retailer client.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Client Id
            type: string
          required: true
          description: ID of the retailer client.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RetailerClientSecretRotated'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - CookieGatedSessionAuth: []
components:
  schemas:
    RetailerClientSecretRotated:
      description: >-
        The client after rotation, with its new secret. The previous secret
        stops working immediately.
      examples:
        - backfill_lookback_days: 90
          client_id: rc_documentationExampleClientIdNotReal
          client_secret: rcs_documentationExampleClientSecretNotReal
          created: '2026-09-07T21:00:00Z'
          id: d5e6f7a8-9012-3456-abcd-ef7890123456
          is_enabled: true
          name: Loyalty backend (production)
          retailer_id: a1b2c3d4-5678-9012-abcd-ef1234567890
          secret_prefix: rcs_Ab3
          sector_identifier: shop.example-retailer.com
          submission_cadence_hours: 24
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        name:
          description: Human-readable label for this credential.
          title: Name
          type: string
        client_id:
          description: Public client identifier. Opaque, stable, safe to log.
          title: Client Id
          type: string
        retailer_id:
          anyOf:
            - description: >-
                URL-safe 22-character shortuuid encoding of the row's UUID
                primary key. Stable across the row's lifetime; suitable for
                sharing in URLs, log lines, and external SDK clients. Accepted
                on input as either the shortuuid form or the canonical UUID form
                (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
              format: shortuuid
              maxLength: 22
              minLength: 22
              pattern: >-
                ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
              type: string
            - type: 'null'
          description: The retailer this client acts as, or null if it is not bound to one.
          title: Retailer Id
        sector_identifier:
          description: >-
            Canonical (lower-cased) host that scopes the pairwise subject
            identifiers issued to this client. Belongs to one organization.
          title: Sector Identifier
          type: string
        backfill_lookback_days:
          description: >-
            How many days back the retailer declares it will backfill purchases
            on first link.
          title: Backfill Lookback Days
          type: integer
        submission_cadence_hours:
          description: How often, in hours, the retailer declares it will submit purchases.
          title: Submission Cadence Hours
          type: integer
        is_enabled:
          description: False while the client's credentials are rejected.
          title: Is Enabled
          type: boolean
        secret_prefix:
          description: >-
            Leading characters of the current secret, for identification only.
            Never sufficient to authenticate.
          title: Secret Prefix
          type: string
        secret_rotated_at:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            ISO 8601 timestamp the secret was last rotated, or null if the
            original is still current.
          title: Secret Rotated At
        last_used:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            ISO 8601 timestamp of the last successful authentication, or null if
            never used.
          title: Last Used
        created:
          description: ISO 8601 timestamp the client was registered.
          title: Created
          type: string
        client_secret:
          description: >-
            The client secret. Returned only in this response; it cannot be
            retrieved again, only rotated.
          title: Client Secret
          type: string
      required:
        - id
        - name
        - client_id
        - sector_identifier
        - backfill_lookback_days
        - submission_cadence_hours
        - is_enabled
        - secret_prefix
        - created
        - client_secret
      title: RetailerClientSecretRotated
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    CookieGatedSessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.