---
title: "Update a link's credentials"
method: PUT
path: "/api/links/{id}/"
tags: ["Links"]
---

# Update a link's credentials

`PUT /api/links/{id}/`

Update the credentials of a specific link. If the successfully updated link is a recurrent one, we automatically trigger an update of the link. If we find fresh data, you'll <a href="https://developers.belvo.com/docs/webhooks" target="_blank">receive historical update</a> webhooks.

> 👍 Use our Connect Widget
>
>  We recommend using our <a href="https://developers.belvo.com/docs/connect-widget" target="_blank">Connect Widget</a> to handle updating <code>invalid</code> or <code>token_required</code> links.

## Path parameters

- `id` string, uuid, required

## Request body

- LinksPutRequest
  - `password` string, required — The end-user's password used to log in to the institution.
  - `password2` string — The end-user's second password used to log in to the institution. > 📘 Info > > This is only required by some institutions. To know which institutions require a second password, see our List institution request and check the `form_fields` array in the response.
  - `token` string — The MFA token generated by the institution which is required to continue a session.

## Response `200`

Ok

- Link
  - `id` string, uuid — Belvo's unique identifier for the current item.
  - `institution` string — Belvo's name for the institution.
  - `access_mode` 'single' | 'recurrent' | 'null', nullable — The link type. For more information, see our <a href="https://developers.belvo.com/docs/links-and-institutions#links" target="_blank">Links</a> article. We return one of the following enum values: - `single` - `recurrent` - `null`
  - `last_accessed_at` string, date-time, nullable — The ISO-8601 timestamp of Belvo's most recent successful access to the institution for the given link.
  - `created_at` string, date-time — The ISO-8601 timestamp of when the data point was created in Belvo's database.
  - `external_id` string — An additional identifier for the link, provided by you, to store in the Belvo database. **Cannot** include any Personal Identifiable Information (PII). **Must** be at least three characters long. If we identify that the identifier contains PII, we will force a `null` value. For more information, see our <a href="https://developers.belvo.com/docs/link-creation-best-practices#adding-your-own-identifier" target="_blank">Link creation article</a>.
  - `institution_user_id` string — > 📘 Info > > Only applicable for links created **after 08-02-2022**. A unique 44-character string that can be used to identify a user at a given institution. 📚 Check out our <a href="https://developers.belvo.com/docs/link-creation-best-practices#avoiding-duplicated-links" target="_blank">Avoiding duplicated links</a> DevPortal article for more information and tips on how to use it.
  - `status` 'valid' | 'invalid' | 'unconfirmed' | 'token_required' — The current status of the link. For more information, see our <a href="https://developers.belvo.com/docs/links-and-institutions#links" target="_blank">Link</a> article in the devportal. We return one of the following values: - `valid` - `invalid` - `unconfirmed` - `token_required`
  - `created_by` string, uuid — The unique ID for the user that created this item.
  - `refresh_rate` '6h' | '12h' | '24h' | '7d' | '30d' | 'null', nullable — The update refresh rate for the recurrent link. For more information, check out our <a href="https://developers.belvo.com/docs/links-and-institutions#recurrent-links" target="_blank">recurrent link documentation</a> in our DevPortal. We return one of the following enum values: - `6h` - `12h` - `24h` - `7d` (default) - `30d` (once a month) - `null` (for single links)
  - `credentials_storage` string — Indicates whether or not to store credentials (and the duration for which to store the credentials). - For recurrent links, this is set to `store` by default (and cannot be changed). - For single links, this is set to `365d` by default. Can be either: - `store` to store credentials (until the link is deleted) - `nostore` to not store credentials - Any value between `1d` and `365d` to indicate the number of days you want the credentials to be stored. For more information, check out the <a href="https://developers.belvo.com/docs/data-retention-controls#credentials_storage" target="_blank">credentials_storage</a> section of our Data retention controls article.
  - `fetch_resources` string[] — An array of resources that you will receive a historical update for.
  - `stale_in` string — Indicates how long any user-derived data should be stored in Belvo's database for the link (both single and recurrent). For example, if you send through `90d`, Belvo will remove any data from its database relating to the user after 90 days. For more information, check out the <a href="https://developers.belvo.com/docs/data-retention-controls#stale_in" target="_blank">stale_in</a> section of our Data retention controls article. > 📘 Info > > Belvo will only remove data for links that have not been updated in the period you provide in `stale_in`. Belvo will only remove data for links that have not been updated in the period you provide in `stale_in`. By default Belvo stores user data for 365 days, unless the link is deleted.

## Other responses

- `400` — Bad request error
- `401` — Unauthorized
- `403` — Access to Belvo API denied
- `404` — Not Found Error
- `428` — MFA Token Required
- `500` — Unexpected Error

---

[API](https://skmtc.net/belvo/apis/belvo-api-docs.md) · [All operations](https://skmtc.net/belvo/apis/belvo-api-docs/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/belvo/belvo-api-docs/versions/3423c786ece5/schema)
