> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivr.thevibecompany.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace connector credential

> Deposit a new credential version to rotate the current one. The secret is encrypted at rest and never returned. Replaying the same key and request is idempotent; a different request under the same key is 409 idempotency_conflict. A disabled instance is 409 connector_disabled. Commits connector.credential_replaced, and connector.health_changed when the evaluated health changes. A deployment without a credential key refuses every rotation with 503 credentials_unavailable (retryable false) before storing or digesting it.



## OpenAPI

````yaml /openapi.yaml put /v0/connectors/{connector_id}/credential
openapi: 3.1.0
info:
  title: Quivr V2 public text foundation contract
  version: 0.0.0-draft
  description: >-
    THE-543 and THE-547 evaluation contracts; endpoint implementations are
    separate work. Matching criterion is plugin-owned and deferred. One
    configured webhook destination, immutable Matches, independent at-least-once
    Delivery and reference-only notifications. OpenAPI is authoritative for
    transport shapes. THE-640 adds text search and asynchronous Corpus
    projection rebuild initiation.
servers: []
security:
  - ApiKey: []
paths:
  /v0/connectors/{connector_id}/credential:
    put:
      tags:
        - Connectors
      summary: Replace connector credential
      description: >-
        Deposit a new credential version to rotate the current one. The secret
        is encrypted at rest and never returned. Replaying the same key and
        request is idempotent; a different request under the same key is 409
        idempotency_conflict. A disabled instance is 409 connector_disabled.
        Commits connector.credential_replaced, and connector.health_changed when
        the evaluated health changes. A deployment without a credential key
        refuses every rotation with 503 credentials_unavailable (retryable
        false) before storing or digesting it.
      operationId: replaceConnectorCredential
      parameters:
        - name: connector_id
          in: path
          required: true
          schema:
            type: string
            minLength: 1
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CredentialReplace'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Connector'
        default:
          description: Structured error; see contract HTTP mapping.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    CredentialReplace:
      type: object
      additionalProperties: false
      properties:
        idempotency_key:
          type: string
          minLength: 1
        secret:
          type: object
          writeOnly: true
        expires_at:
          type: string
          format: date-time
      required:
        - idempotency_key
        - secret
    Connector:
      type: object
      additionalProperties: false
      properties:
        connector_id:
          type: string
          minLength: 1
        corpus_id:
          type: string
          minLength: 1
        source_namespace:
          type: string
          minLength: 1
        kind:
          $ref: '#/components/schemas/ConnectorKind'
        config:
          type: object
        schedule:
          type: object
          additionalProperties: false
          properties:
            interval_seconds:
              type: integer
              minimum: 1
          required:
            - interval_seconds
        health_policy:
          type: object
          additionalProperties: false
          properties:
            silent_after_seconds:
              type: integer
              minimum: 1
            credential_warning_seconds:
              type: integer
              minimum: 0
          required:
            - silent_after_seconds
            - credential_warning_seconds
        enabled:
          type: boolean
        created_at:
          type: string
          format: date-time
        disabled_at:
          type: string
          format: date-time
        credential:
          $ref: '#/components/schemas/CredentialMetadata'
        health:
          $ref: '#/components/schemas/ConnectorHealth'
        webhook_url:
          type: string
          format: uri
          description: >-
            Public address of the instance's webhook route, present when its
            kind declares the push mode and the deployment sets public_url. The
            kind's plugin registers it with the source.
      required:
        - connector_id
        - corpus_id
        - source_namespace
        - kind
        - config
        - schedule
        - health_policy
        - enabled
        - created_at
        - health
    Error:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        message:
          type: string
          minLength: 1
        retryable:
          type: boolean
        field:
          type: string
          minLength: 1
          description: >-
            JSON Pointer (RFC 6901) to the request member that caused a 422,
            when known (for example /config/url or /credential/secret/token on
            connector commands).
        resync_url:
          type: string
          format: uri-reference
      required:
        - code
        - message
        - retryable
    ConnectorKind:
      type: string
      pattern: ^[a-z][a-z0-9_]{0,31}$
      description: >-
        Connector kind, provided by the engine or by a pinned connector plugin;
        listConnectorKinds lists the kinds this deployment accepts. Built-in
        kinds are fixture (a deterministic test connector available only when
        the deployment enables it). First-party connector plugins provide rss
        (RSS 2.0, RSS 1.0, Atom and JSON Feed documents; config url, optional
        honor_ttl; optional credential username+password or token), x_list (an X
        list) and m365_mail (Microsoft 365 mailboxes). Another kind is refused
        with 422 unsupported_connector_kind.
    CredentialMetadata:
      type: object
      additionalProperties: false
      properties:
        version:
          type: integer
          minimum: 1
        deposited_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
      required:
        - version
        - deposited_at
      description: >-
        Metadata of the current Deposited Credential; the secret itself is never
        returned.
    ConnectorHealth:
      type: object
      additionalProperties: false
      properties:
        state:
          type: string
          enum:
            - active
            - silent
            - access_error
            - credential_expiring
            - disabled
        evaluated_at:
          type: string
          format: date-time
        last_success_at:
          type: string
          format: date-time
        last_item_at:
          type: string
          format: date-time
        last_error:
          $ref: '#/components/schemas/ConnectorError'
        usage:
          $ref: '#/components/schemas/ConnectorUsage'
        diagnostics:
          type: object
          description: >-
            Kind-defined diagnostics from the latest acquisition page,
            documented on the kind's operator guide page (for x_list, the
            deletion recheck coverage). Informational; never holds a secret or
            source content.
        push:
          $ref: '#/components/schemas/ConnectorPush'
      required:
        - state
        - evaluated_at
      description: >-
        Last committed Connector Health, evaluated at each acquisition run,
        credential replacement and disable; evaluated_at shows its age.
        Precedence disabled, access_error, credential_expiring, silent, active.
        access_error means the source refused access (distinct from silent,
        which means no new item within the threshold), including a push channel
        refused access while polling carries the collection. Other failures
        appear only as last_error.
    ConnectorError:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        at:
          type: string
          format: date-time
      required:
        - code
        - at
    ConnectorUsage:
      type: object
      additionalProperties: false
      properties:
        day:
          type: string
          pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}$
          description: Current UTC calendar day (YYYY-MM-DD).
        items_read:
          type: integer
          minimum: 0
          description: >-
            Source resources read during the current UTC day, counted as the
            source bills them (for x_list, an estimate of billed post reads
            after X's per-UTC-day deduplication).
        previous_day_items_read:
          type: integer
          minimum: 0
      required:
        - day
        - items_read
        - previous_day_items_read
      description: >-
        Per-UTC-day source read counters, present only for kinds that report
        reads.
    ConnectorPush:
      type: object
      additionalProperties: false
      properties:
        state:
          type: string
          enum:
            - active
            - pending
            - degraded
          description: >-
            active, deliveries are expected; pending, the kind has not set its
            push channel up yet; degraded, the setup failed or deliveries fail
            or miss items, and polling at the instance's interval carries the
            collection.
        error:
          $ref: '#/components/schemas/ConnectorPushError'
        last_delivery_at:
          type: string
          format: date-time
          description: Last delivery the connector plugin accepted.
        poll_interval_seconds:
          type: integer
          minimum: 1
          description: >-
            While push is active, polling runs at most this often, as a safety
            net.
      required:
        - state
      description: >-
        Push delivery health, present once a kind that declares the push mode
        reports its push channel.
    ConnectorPushError:
      type: object
      additionalProperties: false
      properties:
        class:
          type: string
          enum:
            - access
            - transient
            - source
        code:
          type: string
          minLength: 1
          description: >-
            For example webhook_invalid (the source invalidated the webhook),
            plugin_unavailable (a delivery found the plugin down) or
            missed_deliveries (polling found items no delivery brought).
        at:
          type: string
          format: date-time
      required:
        - class
        - code
        - at
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        API key, not necessarily a JWT. Server derives Organization, permitted
        actions and Corpus scope; every resource access is authorized.

````