---
title: "Update application credential"
method: PATCH
path: "/zones/{zoneId}/application-credentials/{id}"
tags: ["Application Credentials"]
---

# Update application credential

`PATCH /zones/{zoneId}/application-credentials/{id}`

Updates an application credential's configuration

## Path parameters

- `zoneId` string, required
- `id` string, required

## Request body

- union — Schema for updating an existing application credential
  - IamTokenCredentialUpdate — Schema for updating a token credential
    - `type` 'token'
    - `subject` string, nullable — Subject identifier for the token. Set to null to unset, which allows any token from the provider to be accepted without checking application-specific claims.
  - IamPasswordCredentialUpdate — Schema for updating a password credential
    - `type` 'password'
  - IamPublicKeyCredentialUpdate — Schema for updating a public key credential
    - `type` 'public-key'
  - IamUrlCredentialUpdate — Schema for updating a URL credential
    - `type` 'url'
    - `identifier` string, uri — URL of the credential (must be a valid URL)
  - IamPublicCredentialUpdate — Schema for updating a public credential
    - `type` 'public'
    - `identifier` string — Identifier for public credential, also used as OAuth 2.0 client ID

## Response `200`

Credentials for accessing external services from applications

- union — Credentials for accessing external services from applications
  - IamApplicationCredentialToken — Common fields shared by all application credential types
    - `id` string, required — Unique identifier of the credential
    - `organization_id` string, required — Organization that owns this credential
    - `zone_id` string, required — Zone this credential belongs to
    - `slug` string, required — URL-safe identifier, unique within the zone
    - `application_id` string, required — ID of the application this credential belongs to
    - `application` IamApplication — An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).
      - `id` string, required — Unique identifier of the application
      - `organization_id` string, required — Organization that owns this application
      - `zone_id` string, required — Zone this application belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `identifier` string, required — User specified identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `metadata` IamMetadata — Entity metadata
        - `docs_url` string, uri — Documentation URL
        - `icon_url` string, uri — Icon URL
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamApplicationOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `redirect_uris` string[], nullable — OAuth 2.0 redirect URIs for this application
          - `post_logout_redirect_uris` string[], nullable — OAuth 2.0 post-logout redirect URIs for this application
      - `dependencies_count` integer, required — Number of resource dependencies
      - `owner_type` 'platform' | 'customer', required — Who owns this application. Platform-owned applications cannot be modified via API.
      - `consent` 'implicit' | 'required', required — Consent mode for the application. 'implicit' means consent is automatically granted, 'required' means explicit user consent is needed.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `created_at` string, date-time, required — Entity creation timestamp
    - `updated_at` string, date-time, required — Entity update timestamp
    - `type` 'token', required
    - `provider_id` string, required — ID of the provider issuing tokens verified by this credential
    - `provider` IamProvider — A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.
      - `id` string, required — Unique identifier of the provider
      - `organization_id` string, required — Organization that owns this provider
      - `zone_id` string, required — Zone this provider belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `identifier` string, required — User specified identifier, unique within the zone
      - `type` 'external' | 'keycard-vault' | 'keycard-sts'
      - `client_id` string, nullable — OAuth 2.0 client identifier
      - `client_secret_set` boolean — Indicates whether a client secret is configured
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamProviderOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `issuer` string, uri, required — OIDC issuer URL used for discovery and token validation.
          - `authorization_endpoint` string, uri, nullable
          - `token_endpoint` string, uri, nullable
          - `registration_endpoint` string, uri, nullable
          - `jwks_uri` string, uri, nullable
          - `code_challenge_methods_supported` string[], nullable
          - `scopes_supported` string[], nullable
          - `authorization_resource_enabled` boolean, nullable — Whether to include the resource parameter in authorization requests.
          - `authorization_resource_parameter` string, nullable — The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.
          - `scope_parameter` string, nullable — The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".
          - `scope_separator` string, nullable — The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".
          - `token_response_access_token_pointer` string, nullable — Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".
          - `authorization_parameters` object, nullable — Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).
        - `openid` IamProviderOpenIDProtocol, nullable — OpenID Connect protocol configuration
          - `userinfo_endpoint` string, uri, nullable
          - `user_identifier_claim` string, nullable — Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.
          - `scopes` string[], nullable — Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).
          - `single_logout_enabled` boolean, nullable — When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.
      - `metadata` object, nullable — Provider metadata
      - `owner_type` 'platform' | 'customer', required — Who owns this provider. Platform-owned providers cannot be modified via API.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `identifier` string, required — Identifier for this credential. For token type, this equals the subject value, or '*' when subject is not specified.
    - `subject` string, nullable — Subject identifier for the token. When null or omitted, any token from the provider is accepted without checking application-specific claims.
  - IamApplicationCredentialPassword — Common fields shared by all application credential types
    - `id` string, required — Unique identifier of the credential
    - `organization_id` string, required — Organization that owns this credential
    - `zone_id` string, required — Zone this credential belongs to
    - `slug` string, required — URL-safe identifier, unique within the zone
    - `application_id` string, required — ID of the application this credential belongs to
    - `application` IamApplication — An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).
      - `id` string, required — Unique identifier of the application
      - `organization_id` string, required — Organization that owns this application
      - `zone_id` string, required — Zone this application belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `identifier` string, required — User specified identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `metadata` IamMetadata — Entity metadata
        - `docs_url` string, uri — Documentation URL
        - `icon_url` string, uri — Icon URL
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamApplicationOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `redirect_uris` string[], nullable — OAuth 2.0 redirect URIs for this application
          - `post_logout_redirect_uris` string[], nullable — OAuth 2.0 post-logout redirect URIs for this application
      - `dependencies_count` integer, required — Number of resource dependencies
      - `owner_type` 'platform' | 'customer', required — Who owns this application. Platform-owned applications cannot be modified via API.
      - `consent` 'implicit' | 'required', required — Consent mode for the application. 'implicit' means consent is automatically granted, 'required' means explicit user consent is needed.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `created_at` string, date-time, required — Entity creation timestamp
    - `updated_at` string, date-time, required — Entity update timestamp
    - `type` 'password', required
    - `identifier` string, required — Username for password credential, also used as OAuth 2.0 client ID
    - `password` string — Password for credential (only returned on creation, store securely), also used as OAuth 2.0 client secret
  - IamApplicationCredentialPublicKey — Common fields shared by all application credential types
    - `id` string, required — Unique identifier of the credential
    - `organization_id` string, required — Organization that owns this credential
    - `zone_id` string, required — Zone this credential belongs to
    - `slug` string, required — URL-safe identifier, unique within the zone
    - `application_id` string, required — ID of the application this credential belongs to
    - `application` IamApplication — An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).
      - `id` string, required — Unique identifier of the application
      - `organization_id` string, required — Organization that owns this application
      - `zone_id` string, required — Zone this application belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `identifier` string, required — User specified identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `metadata` IamMetadata — Entity metadata
        - `docs_url` string, uri — Documentation URL
        - `icon_url` string, uri — Icon URL
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamApplicationOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `redirect_uris` string[], nullable — OAuth 2.0 redirect URIs for this application
          - `post_logout_redirect_uris` string[], nullable — OAuth 2.0 post-logout redirect URIs for this application
      - `dependencies_count` integer, required — Number of resource dependencies
      - `owner_type` 'platform' | 'customer', required — Who owns this application. Platform-owned applications cannot be modified via API.
      - `consent` 'implicit' | 'required', required — Consent mode for the application. 'implicit' means consent is automatically granted, 'required' means explicit user consent is needed.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `created_at` string, date-time, required — Entity creation timestamp
    - `updated_at` string, date-time, required — Entity update timestamp
    - `type` 'public-key', required
    - `identifier` string, required — Client ID for public key credential, also used as OAuth 2.0 client ID
    - `jwks_uri` string, uri, required — JWKS URI to retrieve public keys from
  - IamApplicationCredentialUrl — Common fields shared by all application credential types
    - `id` string, required — Unique identifier of the credential
    - `organization_id` string, required — Organization that owns this credential
    - `zone_id` string, required — Zone this credential belongs to
    - `slug` string, required — URL-safe identifier, unique within the zone
    - `application_id` string, required — ID of the application this credential belongs to
    - `application` IamApplication — An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).
      - `id` string, required — Unique identifier of the application
      - `organization_id` string, required — Organization that owns this application
      - `zone_id` string, required — Zone this application belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `identifier` string, required — User specified identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `metadata` IamMetadata — Entity metadata
        - `docs_url` string, uri — Documentation URL
        - `icon_url` string, uri — Icon URL
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamApplicationOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `redirect_uris` string[], nullable — OAuth 2.0 redirect URIs for this application
          - `post_logout_redirect_uris` string[], nullable — OAuth 2.0 post-logout redirect URIs for this application
      - `dependencies_count` integer, required — Number of resource dependencies
      - `owner_type` 'platform' | 'customer', required — Who owns this application. Platform-owned applications cannot be modified via API.
      - `consent` 'implicit' | 'required', required — Consent mode for the application. 'implicit' means consent is automatically granted, 'required' means explicit user consent is needed.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `created_at` string, date-time, required — Entity creation timestamp
    - `updated_at` string, date-time, required — Entity update timestamp
    - `type` 'url', required
    - `identifier` string, uri, required — URL of the credential (must be a valid URL)
  - IamApplicationCredentialPublic — Common fields shared by all application credential types
    - `id` string, required — Unique identifier of the credential
    - `organization_id` string, required — Organization that owns this credential
    - `zone_id` string, required — Zone this credential belongs to
    - `slug` string, required — URL-safe identifier, unique within the zone
    - `application_id` string, required — ID of the application this credential belongs to
    - `application` IamApplication — An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).
      - `id` string, required — Unique identifier of the application
      - `organization_id` string, required — Organization that owns this application
      - `zone_id` string, required — Zone this application belongs to
      - `slug` string, required — URL-safe identifier, unique within the zone
      - `identifier` string, required — User specified identifier, unique within the zone
      - `name` string, required — Human-readable name
      - `description` string, nullable — Human-readable description
      - `metadata` IamMetadata — Entity metadata
        - `docs_url` string, uri — Documentation URL
        - `icon_url` string, uri — Icon URL
      - `protocols` object, nullable — Protocol-specific configuration
        - `oauth2` IamApplicationOAuth2Protocol, nullable — OAuth 2.0 protocol configuration
          - `redirect_uris` string[], nullable — OAuth 2.0 redirect URIs for this application
          - `post_logout_redirect_uris` string[], nullable — OAuth 2.0 post-logout redirect URIs for this application
      - `dependencies_count` integer, required — Number of resource dependencies
      - `owner_type` 'platform' | 'customer', required — Who owns this application. Platform-owned applications cannot be modified via API.
      - `consent` 'implicit' | 'required', required — Consent mode for the application. 'implicit' means consent is automatically granted, 'required' means explicit user consent is needed.
      - `created_at` string, date-time, required — Entity creation timestamp
      - `updated_at` string, date-time, required — Entity update timestamp
    - `created_at` string, date-time, required — Entity creation timestamp
    - `updated_at` string, date-time, required — Entity update timestamp
    - `type` 'public', required
    - `identifier` string, required — Identifier for public credential, also used as OAuth 2.0 client ID

## Other responses

- `default` — Error response

---

[API](https://skmtc.net/keycardai/apis/untitled-api.md) · [All operations](https://skmtc.net/keycardai/apis/untitled-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/keycardai/untitled-api/revisions/2f5033ed4491/schema)
