{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/openai/main/json-schema/openai-rotate-vault-credential-params-schema.json", "title": "RotateVaultCredentialParams", "description": "Metadata, secret, expiry, and OAuth refresh scope updates for an existing vault credential. Supply at least one of `auth` or `metadata`.", "x-generated": "2026-09-23", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/openai-vaults-api-openapi.yml#/components/schemas/RotateVaultCredentialParams", "type": "object", "properties": { "auth": { "$ref": "#/$defs/RotateVaultCredentialAuthParam", "description": "Replacement values for the credential's existing authentication method." }, "metadata": { "type": "object", "additionalProperties": { "type": "string", "minLength": 0, "maxLength": 512 }, "propertyNames": { "type": "string", "minLength": 1, "maxLength": 64 }, "minProperties": 0, "maxProperties": 16, "description": "Replaces all metadata. Omit to preserve it, or pass {} to clear it. Up to 16 string key-value pairs, with keys up to 64 and values up to 512 characters." } }, "additionalProperties": false, "$defs": { "RotateMcpOauthRefreshParam": { "type": "object", "properties": { "refresh_token": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "The replacement refresh token. Omit or pass `null` to keep the stored token. This secret is never returned in resources." }, "scope": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "Replacement space-separated OAuth scopes for refresh requests. Omit to keep the scopes, or pass `null` to stop sending a scope parameter." }, "token_endpoint_auth": { "anyOf": [ { "$ref": "#/$defs/RotateMcpOauthTokenEndpointAuthParam" }, { "type": "null" } ], "description": "Client-secret updates for the existing token endpoint authentication method." } }, "additionalProperties": false, "description": "Updates to an MCP credential's existing OAuth refresh configuration." }, "RotateMcpOauthTokenEndpointAuthParam": { "oneOf": [ { "$ref": "#/$defs/RotateMcpOauthTokenEndpointAuthParamClientSecretBasic" }, { "$ref": "#/$defs/RotateMcpOauthTokenEndpointAuthParamClientSecretPost" } ], "x-oai-discriminator-values": [ "client_secret_basic", "client_secret_post" ], "description": "Client-secret updates that preserve the credential's OAuth authentication method." }, "RotateMcpOauthTokenEndpointAuthParamClientSecretBasic": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "client_secret_basic" ], "default": "client_secret_basic", "x-stainless-const": true, "description": "The type of the object. Always `client_secret_basic`." }, "client_secret": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "The replacement OAuth client secret. Omit or pass `null` to keep the stored secret. This secret is never returned in resources." } }, "required": [ "type" ], "additionalProperties": false, "description": "Updates credentials sent using HTTP Basic authentication." }, "RotateMcpOauthTokenEndpointAuthParamClientSecretPost": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "client_secret_post" ], "default": "client_secret_post", "x-stainless-const": true, "description": "The type of the object. Always `client_secret_post`." }, "client_secret": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "The replacement OAuth client secret. Omit or pass `null` to keep the stored secret. This secret is never returned in resources." } }, "required": [ "type" ], "additionalProperties": false, "description": "Updates credentials sent in the token request body." }, "RotateVaultCredentialAuthParam": { "oneOf": [ { "$ref": "#/$defs/RotateVaultCredentialAuthParamMcpOauth" }, { "$ref": "#/$defs/RotateVaultCredentialAuthParamStaticBearer" }, { "$ref": "#/$defs/RotateVaultCredentialAuthParamEnvironmentVariable" } ], "x-oai-discriminator-values": [ "mcp_oauth", "static_bearer", "environment_variable" ], "description": "Updates to a vault credential without changing its authentication method or destination configuration." }, "RotateVaultCredentialAuthParamEnvironmentVariable": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "environment_variable" ], "default": "environment_variable", "x-stainless-const": true, "description": "The type of the object. Always `environment_variable`." }, "secret_value": { "type": "string", "minLength": 1, "maxLength": 1048576, "description": "The write-only replacement secret. Never returned in credential resources or supplied directly to sandbox code. Must be nonempty and must not contain carriage returns, newlines, or NUL bytes." } }, "required": [ "type", "secret_value" ], "additionalProperties": false, "description": "Replace the secret for an OpenAI-hosted environment credential. The environment variable name and networking configuration remain unchanged." }, "RotateVaultCredentialAuthParamMcpOauth": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "mcp_oauth" ], "default": "mcp_oauth", "x-stainless-const": true, "description": "The type of the object. Always `mcp_oauth`." }, "access_token": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "A write-only replacement OAuth access token." }, "expires_at": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "The replacement expiry as an RFC 3339 timestamp, or `null` to clear it. Omitting this field preserves the expiry unless a new access token is supplied, in which case the expiry is cleared." }, "refresh": { "anyOf": [ { "$ref": "#/$defs/RotateMcpOauthRefreshParam" }, { "type": "null" } ], "description": "Optional write-only refresh-token and client-secret updates." } }, "required": [ "type" ], "additionalProperties": false, "description": "Rotate an OAuth credential for an HTTPS MCP destination." }, "RotateVaultCredentialAuthParamStaticBearer": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "static_bearer" ], "default": "static_bearer", "x-stainless-const": true, "description": "The type of the object. Always `static_bearer`." }, "token": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The replacement bearer token. This secret is never returned in credential resources." } }, "required": [ "type", "token" ], "additionalProperties": false, "description": "Replace the bearer token for the credential's MCP server." } } }