Skip to main content
POST
Rotate a registered extension's secret

Autorizações

Authorization
string
header
obrigatório

Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.

Parâmetros de caminho

publisher
string
obrigatório

The publisher half of the extension's namespaced name.

The name is publisher/extension and travels as TWO path segments rather than one. The single-segment spelling is not broken — a generated client percent-encodes a path parameter's slash and the router decodes it back — so this is a deployment choice rather than a repair: an encoded slash is normalised or rejected by most reverse proxies a hosted home sits behind, and two segments read the way the name reads, /v1/extensions/lerian/redactor.

Pattern: ^[a-z0-9][a-z0-9-]*$
Exemplo:

"lerian"

name
string
obrigatório

The extension half of the namespaced name.

Pattern: ^[a-z0-9][a-z0-9-]*$
Exemplo:

"redactor"

Resposta

The new secret, and when the superseded one stops being accepted. The secret appears here and in the registration's response and nowhere else, ever.

A freshly rotated secret, shown exactly once.

secret
string
obrigatório

The new secret. Nothing in this contract will produce it again.

previousValidUntil
string<date-time>

When the superseded secret stops being accepted.