---
title: "Rotate"
method: POST
path: "/api/v1/decoys/{id}/rotate"
tags: ["Decoy"]
---

# Rotate

`POST /api/v1/decoys/{id}/rotate`

Rotate re-mints the paired credential's secret material, preserves
 the decoy_id binding, and returns the new one-time vending material.

## Path parameters

- `id` string, required — The id field.

## Request body

- C1ApiDecoyV1DecoyServiceRotateRequestInput — The DecoyServiceRotateRequest message.

## Response `200`

Successful response

- C1ApiDecoyV1DecoyServiceRotateResponse — The DecoyServiceRotateResponse message.
  - `decoy` C1ApiDecoyV1Decoy — Decoy is the read projection of a planted honey-credential. All fields except annotations are server-managed.
    - `annotations` object — Customer-defined grouping/filtering bag. PATCH semantics on Update: keys in the request overwrite, keys missing stay, keys set to empty string delete. Copied onto the Finding produced when a decoy fires, so routing rules can condition on the same keys.
    - `createdAt` string, date-time, nullable
    - `description` string — The description field.
    - `disabled` boolean — Admin-disabled.
    - `displayName` string — The displayName field.
    - `id` string — The id field.
    - `kind` 'DECOY_KIND_UNSPECIFIED' | 'DECOY_KIND_USER_CLIENT_CREDENTIAL' | 'DECOY_KIND_CONNECTOR_CLIENT' | 'DECOY_KIND_WORKLOAD_FEDERATION' | 'DECOY_KIND_ACCESS_TOKEN' — The kind field.
    - `lastUsedAt` string, date-time, nullable
    - `materialFingerprintSha256` string — Hex-encoded SHA256 of the secret string vended at Create / Rotate. Stable for the decoy's current material; changes only on Rotate. Empty for WorkloadFederation decoys (no server-vended secret).
    - `updatedAt` string, date-time, nullable
  - `material` C1ApiDecoyV1DecoyVendingMaterial — DecoyVendingMaterial carries the freshly-vended secret material returned exactly once at Create or Rotate. This message contains a oneof named material. Only a single field of the following list may be set at a time: - clientCredential - accessToken - workloadFederation
    - `accessToken` C1ApiDecoyV1DecoyAccessTokenMaterial — DecoyAccessTokenMaterial is returned for AccessToken decoys.
      - `accessToken` string — The accessToken field.
    - `clientCredential` C1ApiDecoyV1DecoyClientCredentialMaterial — DecoyClientCredentialMaterial is returned for UserClientCredential and ConnectorClient decoys.
      - `clientId` string — The clientId field.
      - `clientSecret` string — The clientSecret field.
    - `workloadFederation` C1ApiDecoyV1DecoyWorkloadFederationMaterial — DecoyWorkloadFederationMaterial is returned for WorkloadFederation decoys. No vended secret; the operator binds the trust on the IdP side.
      - `workloadFederationTrustId` string — The workloadFederationTrustId field.

---

[API](https://skmtc.net/conductorone/apis/c1-api.md) · [All operations](https://skmtc.net/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/conductorone/c1-api/revisions/f2cf3228f366/schema)
