---
title: "UpdateSCMCredential updates the SCM credential specified in the request."
method: PATCH
path: "/v1/namespaces/{object.tenant_meta.namespace}/scm-credentials"
tags: ["SCMCredentialService"]
---

# UpdateSCMCredential updates the SCM credential specified in the request.

`PATCH /v1/namespaces/{object.tenant_meta.namespace}/scm-credentials`

## Path parameters

- `object.tenant_meta.namespace` string, required

## Request body

- SCMCredentialServiceUpdateSCMCredentialBody — Request to update an SCM credential.
  - `object` object — SCMCredential represents SCM org/repo credentials for private dependency resolution. Customers configure these credentials to allow endorctl to authenticate with private Git repositories during agentless or SCM-integrated scans, eliminating resolution failures for cross-org private dependencies.
    - `meta` V1Meta — Common fields for all Endor Labs resources.
      - `annotations` object — Annotations can be used to attach metadata to a resource message. Annotation values can be small or large, structured or unstructured, and may include characters not permitted by labels. The keys may contain alphanumerics, underscores (_), dots (.) and dashes (-). The values of an annotation must be 16384 bytes or smaller.
      - `create_time` string, date-time — Time the resource was created. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
      - `created_by` string — Name and authentication source of the user who created the object, for example, ewok@endor.ai@google@api-key.
      - `description` string — Resource description. Must be less than 1024 bytes.
      - `index_data` V1IndexData — IndexData is used to index the resource for search. It's an internal object.
        - `data` string[]
        - `search_score` number, float — search_score is the score of the resource for search. Internal use only.
        - `tenant` string
        - `will_be_deleted_at` string, date-time — Time that the resource will be deleted.
      - `kind` string — Resource kind, for example, HelloResponse. Auto-generated using the protobuf message proto.MessageName().Name().
      - `name` string, required — Resource name. Must be 63 characters or less.
      - `parent_kind` string — Parent object resource kind, for example, Project.
      - `parent_uuid` string — Parent object UUID.
      - `references` object — Map of objects referenced in a query API.
      - `tags` string[] — List of tags attached to the resource. Tags can be used to select objects and to find collections of objects that satisfy certain conditions. A tag must be 255 characters or less.
      - `update_time` string, date-time — Time the resource was last updated. Note: Updated on all create/patch/delete operations. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
      - `updated_by` string — Name and authentication source of the last user who updated the object, for example, vulnerabilityingestor@endor.ai@x509.
      - `upsert_time` string, date-time — Time the resource was last upserted. Note: create_time is only set the first time the resource is created. upsert_time is set every time the resource is upseted. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
      - `version` string — Message version.
    - `propagate` boolean — Propagate indicates that the object should be visible in child namespaces.
    - `spec` V1SCMCredentialSpec
      - `access_token` string, required — Access token for authenticating to the SCM platform. Used for HTTPS-based Git operations (e.g., git URL rewrites). Works across all SCM providers: GitHub PAT, GitLab PAT, Bitbucket access token, Azure DevOps PAT, etc. The secure annotation ensures automatic redaction and secure storage.
      - `description` string
      - `platform_source` 'PLATFORM_SOURCE_UNSPECIFIED' | 'PLATFORM_SOURCE_GITHUB' | 'PLATFORM_SOURCE_GITLAB' | 'PLATFORM_SOURCE_GITSERVER' | 'PLATFORM_SOURCE_BITBUCKET' | 'PLATFORM_SOURCE_BINARY' | 'PLATFORM_SOURCE_HUGGING_FACE' | 'PLATFORM_SOURCE_AZURE' | 'PLATFORM_SOURCE_ARCHIVE' | 'PLATFORM_SOURCE_EXTERNAL_AI_SERVICE' | 'PLATFORM_SOURCE_GITHUB_ENTERPRISE', required — Type of source control platform a resource was discovered on.
      - `scm_credential_status` SpecSCMCredentialStatus
        - `error_message` string — error_message if any was found.
        - `last_tested_at` string, date-time — last_tested_at is the time when the credential was last tested.
        - `state` 'STATE_UNSPECIFIED' | 'STATE_SUCCESS' | 'STATE_FAIL' — The status of the SCM credential. - STATE_FAIL: STATE_FAIL covers all failure modes: unreachable host, invalid token, and expired token. Inspect error_message for the specific cause.
      - `target_url` string, required — The target URL of the SCM org or repo for which this credential applies. Examples: - Org-level: "https://github.com/myorg" - Repo-level: "https://github.com/myorg/private-repo" Git URL rewrites will be applied for all sub-paths of this URL.
    - `tenant_meta` object — Namespaces are associated with a tenant.
    - `uuid` string — The UUID of the SCM credential.
  - `request` V1UpdateRequest — Message used for all update requests.
    - `force` boolean — Force will force the update of the resource if any checks fail.
    - `update_mask` string — Fields to update. Defaults to all fields.

## Response `200`

A successful response.

- V1SCMCredential — SCMCredential represents SCM org/repo credentials for private dependency resolution. Customers configure these credentials to allow endorctl to authenticate with private Git repositories during agentless or SCM-integrated scans, eliminating resolution failures for cross-org private dependencies.
  - `meta` V1Meta, required — Common fields for all Endor Labs resources.
    - `annotations` object — Annotations can be used to attach metadata to a resource message. Annotation values can be small or large, structured or unstructured, and may include characters not permitted by labels. The keys may contain alphanumerics, underscores (_), dots (.) and dashes (-). The values of an annotation must be 16384 bytes or smaller.
    - `create_time` string, date-time — Time the resource was created. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
    - `created_by` string — Name and authentication source of the user who created the object, for example, ewok@endor.ai@google@api-key.
    - `description` string — Resource description. Must be less than 1024 bytes.
    - `index_data` V1IndexData — IndexData is used to index the resource for search. It's an internal object.
      - `data` string[]
      - `search_score` number, float — search_score is the score of the resource for search. Internal use only.
      - `tenant` string
      - `will_be_deleted_at` string, date-time — Time that the resource will be deleted.
    - `kind` string — Resource kind, for example, HelloResponse. Auto-generated using the protobuf message proto.MessageName().Name().
    - `name` string, required — Resource name. Must be 63 characters or less.
    - `parent_kind` string — Parent object resource kind, for example, Project.
    - `parent_uuid` string — Parent object UUID.
    - `references` object — Map of objects referenced in a query API.
    - `tags` string[] — List of tags attached to the resource. Tags can be used to select objects and to find collections of objects that satisfy certain conditions. A tag must be 255 characters or less.
    - `update_time` string, date-time — Time the resource was last updated. Note: Updated on all create/patch/delete operations. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
    - `updated_by` string — Name and authentication source of the last user who updated the object, for example, vulnerabilityingestor@endor.ai@x509.
    - `upsert_time` string, date-time — Time the resource was last upserted. Note: create_time is only set the first time the resource is created. upsert_time is set every time the resource is upseted. Format: 2017-01-15T01:30:15.01Z RFC 3339: https://www.ietf.org/rfc/rfc3339.txt.
    - `version` string — Message version.
  - `propagate` boolean — Propagate indicates that the object should be visible in child namespaces.
  - `spec` V1SCMCredentialSpec, required
    - `access_token` string, required — Access token for authenticating to the SCM platform. Used for HTTPS-based Git operations (e.g., git URL rewrites). Works across all SCM providers: GitHub PAT, GitLab PAT, Bitbucket access token, Azure DevOps PAT, etc. The secure annotation ensures automatic redaction and secure storage.
    - `description` string
    - `platform_source` 'PLATFORM_SOURCE_UNSPECIFIED' | 'PLATFORM_SOURCE_GITHUB' | 'PLATFORM_SOURCE_GITLAB' | 'PLATFORM_SOURCE_GITSERVER' | 'PLATFORM_SOURCE_BITBUCKET' | 'PLATFORM_SOURCE_BINARY' | 'PLATFORM_SOURCE_HUGGING_FACE' | 'PLATFORM_SOURCE_AZURE' | 'PLATFORM_SOURCE_ARCHIVE' | 'PLATFORM_SOURCE_EXTERNAL_AI_SERVICE' | 'PLATFORM_SOURCE_GITHUB_ENTERPRISE', required — Type of source control platform a resource was discovered on.
    - `scm_credential_status` SpecSCMCredentialStatus
      - `error_message` string — error_message if any was found.
      - `last_tested_at` string, date-time — last_tested_at is the time when the credential was last tested.
      - `state` 'STATE_UNSPECIFIED' | 'STATE_SUCCESS' | 'STATE_FAIL' — The status of the SCM credential. - STATE_FAIL: STATE_FAIL covers all failure modes: unreachable host, invalid token, and expired token. Inspect error_message for the specific cause.
    - `target_url` string, required — The target URL of the SCM org or repo for which this credential applies. Examples: - Org-level: "https://github.com/myorg" - Repo-level: "https://github.com/myorg/private-repo" Git URL rewrites will be applied for all sub-paths of this URL.
  - `tenant_meta` V1TenantMeta, required — Tenant related data for the tenant containing the resource.
    - `namespace` string, required — Namespaces are a way to organize organizational units into virtual groupings of resources. Namespaces must be a fully qualified name, for example, the child namespace of namespace "endor.prod" called "app" is called "endor.prod.app".
  - `uuid` string — The UUID of the SCM credential.

## Other responses

- `default` — An unexpected error response.

---

[API](https://skmtc.net/endorlabs/apis/endor-labs-rest-api-reference.md) · [All operations](https://skmtc.net/endorlabs/apis/endor-labs-rest-api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/endorlabs/endor-labs-rest-api-reference/revisions/2fe1f84213b3/schema)
