Update a credential
Partially updates a credential owned by the authenticated integrator: label, active, and
accessScope can each be changed independently; omitted fields are left untouched. The
credential signing the current request can only change its own label, not its own active
status or access scope, so an integrator always keeps one working read-write credential.
Requires a read-write credential.
Authorizations
Headers
Integrator's ECDSA public key (P-256 curve, compressed SEC1 format). Example: 0x038fedef7c12f93bbf342ad8943b7a825a3b41f61c9dc118b2c718efebabbf62fd
Unix timestamp in seconds (UTC). Must be within tolerance window (1 minute) to prevent replay attacks. Example: 1760375826
ECDSA signature (DER-encoded, hex with 0x prefix). Signs the message: {timestamp}{METHOD}{path_and_query}{json_body}. Example: 0x3045022100...
Path Parameters
Public key of the credential
Body
Response
Credential updated
Public key identifying the credential.
A UUID string
"550e8400-e29b-41d4-a716-446655440000"
read_write, read_only "read_write"
Whether the credential is active.
Label of the credential.

