Rotate a registered extension's secret
Mints a new secret and returns it once. The response names when the old one stops being accepted. Requires extensions:manage.
A row Lerian installed cannot be rotated here, for the reason it cannot be revoked: the secret is what Lerian authenticates with, and the owner’s power over such a row is the standing veto.
Autorizações
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parâmetros de caminho
The publisher half of the extension's namespaced name.
The name is publisher/extension and travels as TWO path segments rather than one. The single-segment spelling is not broken — a generated client percent-encodes a path parameter's slash and the router decodes it back — so this is a deployment choice rather than a repair: an encoded slash is normalised or rejected by most reverse proxies a hosted home sits behind, and two segments read the way the name reads, /v1/extensions/lerian/redactor.
^[a-z0-9][a-z0-9-]*$"lerian"
The extension half of the namespaced name.
^[a-z0-9][a-z0-9-]*$"redactor"
Resposta
The new secret, and when the superseded one stops being accepted. The secret appears here and in the registration's response and nowhere else, ever.

