> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a registered extension's secret

> Mints a new secret and returns it once. The response names when the old one stops being accepted. Requires `extensions:manage`.

**A row Lerian installed cannot be rotated here**, for the reason it cannot be revoked: the secret is what Lerian authenticates with, and the owner's power over such a row is the standing veto.



## OpenAPI

````yaml /en/openapi/v3-current/narya.yaml post /v1/extensions/{publisher}/{name}/secret
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    serves this API over a Unix socket in your Narya home. The terminal client
    and the one-shot command that Lerian ships drive this API, and a client you
    write drives the same one.


    Requests authenticate with a bearer token issued by the identity provider
    the host is configured with. An operation that declares another security
    scheme also accepts that credential. A request without a valid credential
    gets 401 with NRY-0011. A caller whose role lacks the permission an
    operation needs gets 403 with NRY-0028.


    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title and message. Codes are NRY- followed by four
    digits. Cursors are opaque.
servers: []
security:
  - bearerAuth: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: extensions
    description: >-
      Host-side extensions and the operations each exposes over the wire. This
      is the generic lane a host extension uses to serve its own client half (a
      TUI component, a web panel) or any API-only consumer, without adding
      routes to this contract.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: environments
    description: >-
      Where a session's code lives and its commands run — this machine, or a
      container narya operates. A session that names none runs here.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
  - name: sharing
    description: >-
      Publishing a session from a developer's own home to the organisation's,
      and what is held back before a byte leaves the machine.
  - name: refinements
    description: >-
      What this owner has taught narya and allowed it to keep — distilled facts,
      and the skills, agents and commands the model wrote for itself. Propose,
      read, consent, roll back. Nothing here fires until a person answers.
  - name: platform
    description: >-
      Calls Lerian's control plane made to a home it hosts, as this home
      recorded them.
paths:
  /v1/extensions/{publisher}/{name}/secret:
    parameters:
      - $ref: '#/components/parameters/ExtensionPublisherParam'
      - $ref: '#/components/parameters/ExtensionNameParam'
    post:
      tags:
        - extensions
      summary: Rotate a registered extension's secret
      description: >-
        Mints a new secret and returns it once. The response names when the old
        one stops being accepted. Requires `extensions:manage`.


        **A row Lerian installed cannot be rotated here**, for the reason it
        cannot be revoked: the secret is what Lerian authenticates with, and the
        owner's power over such a row is the standing veto.
      operationId: rotateExtensionSecret
      responses:
        '200':
          description: >-
            The new secret, and when the superseded one stops being accepted.
            The secret appears here and in the registration's response and
            nowhere else, ever.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExtensionSecret'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          description: >-
            The caller's role does not carry `extensions:manage`, or the row is
            operator-installed and may only be disabled (NRY-0028).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    ExtensionPublisherParam:
      name: publisher
      in: path
      required: true
      description: >-
        The publisher half of the extension's namespaced name.


        The name is `publisher/extension` and travels as TWO path segments
        rather than one. The single-segment spelling is not broken — a generated
        client percent-encodes a path parameter's slash and the router decodes
        it back — so this is a deployment choice rather than a repair: an
        encoded slash is normalised or rejected by most reverse proxies a hosted
        home sits behind, and two segments read the way the name reads,
        `/v1/extensions/lerian/redactor`.
      schema:
        type: string
        pattern: ^[a-z0-9][a-z0-9-]*$
        examples:
          - lerian
    ExtensionNameParam:
      name: name
      in: path
      required: true
      description: The extension half of the namespaced name.
      schema:
        type: string
        pattern: ^[a-z0-9][a-z0-9-]*$
        examples:
          - redactor
  schemas:
    ExtensionSecret:
      type: object
      description: A freshly rotated secret, shown exactly once.
      required:
        - secret
      properties:
        secret:
          type: string
          description: The new secret. Nothing in this contract will produce it again.
        previousValidUntil:
          type: string
          format: date-time
          description: When the superseded secret stops being accepted.
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.
  responses:
    Unauthorized:
      description: >-
        Authentication required — a request carrying no valid identity token
        (NRY-0011).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The addressed resource does not exist on this host.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Enforced on every transport, with no exempt operation. A person's
        request — over the default local unix socket exactly as over a TCP
        listener — must carry a JWT issued by the configured identity provider,
        which the host verifies itself against that issuer's key set: signature,
        issuer, expiry, and the person and organisation it names. Requests
        without a valid one receive 401 NRY-0011. The socket's file permissions
        are transport and are not an authorisation.

````