---
# @generated by sylphx-gen 0.1.0 from contracts@f99a9bda63ea35002f40ef41b07b570c1c970750996f232cbfb0ed12313637ab. Do not edit.
title: "Rotate credential on an agent"
description: "`agents.agents.rotate_credential` (POST /v1/{parent}/agents:rotate-credential): Rotates the captured value under the same handle with generation fencing."
type: reference
product: agents
summary: "Rotates the captured value under the same handle with generation fencing."
updated: 2026-09-28
nav: false
---

Rotates the captured value under the same handle with generation fencing.

**Not available yet.** Sylphx Agents is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents:rotate-credential`
- **Scope** `agents:sessions`
- **Effect** `write` — a successful call changes state.
- **Collection** [agents](/docs/api/agents)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The environment that owns the captured handle. Required. |
| `handle` | `string` | The opaque handle whose captured credential is being replaced. Required. Never returned again. |
| `generation` | `int64` | The current handle generation; stale rotations are refused. Required. |
| `credential` | `string` | The replacement issuer-provided credential, stored encrypted. Required. Never returned again. |
| `expires_at` | `timestamp` | The issuer-provided expiry of the replacement credential. Required. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `handle` | `string` | The opaque handle; it never reveals the captured credential. Output only. Never returned again. |
| `generation` | `int64` | The current fencing generation of the captured handle. Output only. |
| `expires_at` | `timestamp` | The issuer-provided expiry of the captured credential. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents:rotate-credential" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"credential":"…","expires_at":{},"generation":1,"handle":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.agents.agents.rotateCredential({ credential: '…', expiresAt: {}, generation: 1, handle: '…', parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::agents::RotateCredentialRequest::default();
req.credential = "…".to_string();
req.expires_at = Some(Default::default());
req.generation = 1;
req.handle = "…".to_string();
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.agents().agents().rotate_credential(req).await?;
```

**CLI**

```bash
sylphx agents agents rotate-credential orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "agents.agents.rotate_credential", "args": {"credential":"…","expires_at":{},"generation":1,"handle":"…","parent":"orgs/acme/projects/shop/envs/production"} }
```
