v7

OpenAPI 3.1.02026-08-06211328764.1 KB
Connections

Rotate dbt commit signing key

Rotate the commit signing keypair for a GitHub App dbt connection and return the dbt configuration with the new commitSigningPublicKey to register on the committer’s GitHub user. Omni mints a fresh Ed25519 keypair unless signingPrivateKey supplies your own (with signingKeyPassphrase when encrypted), enabling zero-downtime rotation: register the matching public key on GitHub first, then set it here. The committer identity can be changed in the same call, so signing can be moved to a different GitHub user in one step. Commits already signed with the old key stay Verified only while the old public key remains registered on GitHub. Only valid for github_app auth.

post/api/v1/connections/{connectionId}/dbt/rotate-signing-key

Path parameters

connectionIdstring uuid required

Connection ID

Example:550e8400-e29b-41d4-a716-446655440000

Connection ID

Request body

commitSigningCommitterEmailstring email nullable

Verified email of the GitHub user that owns the registered signing key, written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterName.

commitSigningCommitterNamestring nullable

Display name written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterEmail.

signingKeyPassphrasestring

Passphrase for signingPrivateKey when it is encrypted. Omni uses it once to decrypt the key, then stores the key under its own encryption at rest; the passphrase itself is not retained.

signingPrivateKeystring

Bring-your-own ED25519 signing private key in PEM format (as produced by ssh-keygen -t ed25519), used instead of an Omni-generated keypair. Enables zero-downtime rotation: register the matching public key on the GitHub user first, then set it here. RSA keys are rejected — commit signing is SSHSIG over ED25519. Must be non-blank when provided; omit it to have Omni mint a fresh keypair.

Example request

{
  "commitSigningCommitterEmail": "omni-bot@example.com",
  "commitSigningCommitterName": "Omni Bot"
}

Response

Signing key rotated; response includes the new public key

authMethod'ssh' | 'https_token' | 'github_app' required

Authentication method for the git repository. "ssh" for deploy key, "https_token" for deploy token/PAT, "github_app" for a GitHub App installation.

autogenRelationshipsboolean required

Whether relationships are auto-generated from dbt

branchstring required

Git branch name

commitSigningCommitterEmailstring nullable required

Verified email of the GitHub user that owns the registered signing key. Null unless a commit signer is configured (github_app auth only).

commitSigningCommitterNamestring nullable required

Display name written into signed commits. Null unless a commit signer is configured (github_app auth only).

commitSigningPublicKeystring nullable required

SSH public key to register as a signing key on the GitHub user that owns commitSigningCommitterEmail, so commits show as Verified. Null for non-github_app auth.

dbtVersionstring required

dbt version being used

enableSemanticLayerboolean required

Whether the dbt semantic layer integration is enabled

enableVirtualSchemasboolean required

Whether virtual schemas are enabled

githubAppInstallationIdstring nullable required

GitHub App installation ID. Null for non-github_app auth.

projectRootPathstring nullable required

Path to dbt project root

sshUrlstring required

Clone URL for the git repository — SSH (git@...) for ssh auth, https:// for https_token or github_app auth

supportsDbttrue required

Indicates dbt is supported and configured

Example response

{
  "authMethod": "ssh",
  "autogenRelationships": true,
  "branch": "main",
  "commitSigningCommitterEmail": "omni-bot@example.com",
  "commitSigningCommitterName": "Omni Bot",
  "dbtVersion": "Auto",
  "githubAppInstallationId": "12345678",
  "projectRootPath": "dbt_project",
  "sshUrl": "git@github.com:org/repo.git",
  "supportsDbt": true
}