> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivr.thevibecompany.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a push token with five minutes of overlap

> Requires connectors:admin on the instance's Organization and Corpus. Atomically issue a new token and mark this token rotated, valid for exactly five more minutes. The replacement has a new token_id and its secret is shown once with Cache-Control no-store. A revoked or already-rotated token is 409 token_inactive; repeating rotation cannot extend the overlap or reveal a secret again. Disabled instances are 409 connector_disabled. Revocation can cut the overlap short. No request body is needed; a lost response requires fresh issuance.



## OpenAPI

````yaml /openapi.yaml post /v0/connectors/{connector_id}/tokens/{token_id}/rotate
openapi: 3.1.0
info:
  title: Quivr HTTP API
  version: 0.0.0-draft
  description: >-
    Every endpoint of the Quivr v0 HTTP API. Send an API key as a bearer token;
    the key decides the Organization, the actions and the Corpora a request may
    reach.
servers: []
security:
  - ApiKey: []
paths:
  /v0/connectors/{connector_id}/tokens/{token_id}/rotate:
    parameters:
      - name: connector_id
        in: path
        required: true
        schema:
          type: string
          minLength: 1
      - name: token_id
        in: path
        required: true
        schema:
          type: string
          minLength: 1
    post:
      tags:
        - Connectors
      summary: Replace a push token with five minutes of overlap
      description: >-
        Requires connectors:admin on the instance's Organization and Corpus.
        Atomically issue a new token and mark this token rotated, valid for
        exactly five more minutes. The replacement has a new token_id and its
        secret is shown once with Cache-Control no-store. A revoked or
        already-rotated token is 409 token_inactive; repeating rotation cannot
        extend the overlap or reveal a secret again. Disabled instances are 409
        connector_disabled. Revocation can cut the overlap short. No request
        body is needed; a lost response requires fresh issuance.
      operationId: rotateConnectorToken
      responses:
        '201':
          description: Replacement token with its one-time bearer secret.
          headers:
            Cache-Control:
              schema:
                type: string
                enum:
                  - no-store
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectorTokenCreated'
        default:
          description: >-
            JSON Error envelope; 401 unauthenticated, 403 without admin
            permission, 404 unknown or foreign token, 409 inactive or disabled,
            503 unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ConnectorTokenCreated:
      type: object
      additionalProperties: false
      required:
        - token
        - secret
      properties:
        token:
          $ref: '#/components/schemas/ConnectorToken'
        secret:
          type: string
          description: >-
            One-time bearer secret; never persisted or returned by metadata
            reads.
    Error:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        message:
          type: string
          minLength: 1
        retryable:
          type: boolean
        field:
          type: string
          minLength: 1
          description: >-
            JSON Pointer (RFC 6901) to the request member that caused a 422,
            when known (for example /config/url or /credential/secret/token on
            connector commands).
        resync_url:
          type: string
          format: uri-reference
      required:
        - code
        - message
        - retryable
    ConnectorToken:
      type: object
      additionalProperties: false
      required:
        - token_id
        - prefix
        - created_at
      properties:
        token_id:
          type: string
        prefix:
          type: string
          description: Display prefix only; cannot authenticate.
        created_at:
          type: string
          format: date-time
        rotated_at:
          type: string
          format: date-time
        revoked_at:
          type: string
          format: date-time
        valid_until:
          type: string
          format: date-time
          description: >-
            Exclusive expiry of an old token after rotation; absent for an
            unrotated token.
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        API key, not necessarily a JWT. Server derives Organization, permitted
        actions and Corpus scope; every resource access is authorized.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.