---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Rotate credentials on a bucket"
description: "`data.buckets.rotate_credentials` (POST /v1/{name}:rotateCredentials): Replaces the bucket's engine credentials; the old ones stop working once the new ones are served."
type: reference
product: storage
summary: "Replaces the bucket's engine credentials; the old ones stop working once the new ones are served."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Replaces the bucket's engine credentials; the old ones stop working once the new ones are served.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/buckets/bucket:rotateCredentials`
- **Scope** `data:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [buckets](/docs/api/buckets)
- **Validate-only** `validate_only=true` runs every check and writes nothing
- **Operation** answers with an `Operation`; the result is `Bucket`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The name of the bucket. Required. |
| `etag` | `string` | Act only if the current etag matches. |
| `validate_only` | `bool` | Validate without acting. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `{parent-of-target}/operations/{operation}`. |
| `target` | `string` | The name of the Resource being changed. |
| `target_generation` | `int64` | The generation this Operation waits for. |
| `verb` | `OperationVerb` | What the Operation does. One of `create`, `update`, `delete`, `custom`. |
| `custom_verb` | `string` | The custom method verb when `verb` is CUSTOM, for example `revoke`. |
| `done` | `bool` | Whether the Operation has finished. |
| `create_time` | `timestamp` | When the Operation started. |
| `end_time` | `timestamp` | When the Operation finished. |
| `response` | `any` | The settled Resource (or Empty for a delete). One of the `result` group. |
| `error` | `ProblemDetails` | The failure, as the one error body. One of the `result` group. |
| `progress` | `OperationProgress` | Progress while not `done`. |

### ProblemDetails

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | `https://sylphx.com/docs/errors/<code in kebab-case>`. |
| `title` | `string` | A short customer-safe summary of the problem class. |
| `status` | `int32` | The HTTP status, fixed by `grpc_status`. |
| `detail` | `string` | A customer-safe explanation of this occurrence. Never contains SQL, stack traces, internal hostnames, or another tenant's data. |
| `instance` | `string` | The request id (`Sylphx-Request-Id`). |
| `code` | `string` | The stable UPPER_SNAKE code, one of ErrorCode without its prefix. |
| `grpc_status` | `string` | One of the 16 canonical gRPC status names, for example `ABORTED`. |
| `retryable` | `bool` | Whether the same request may be retried. |
| `effect` | `ErrorEffect` | What the failed call committed. One of `none`, `applied`, `unknown`. |
| `retry_after_ms` | `int64` | How long to wait before retrying, when the server knows. |
| `details` | `any[]` | Typed details such as PreconditionFailure or EntitlementDenial. |

### OperationProgress

| Field | Type | What it is |
| --- | --- | --- |
| `percent` | `int32` | Percent complete, when the controller can tell. |
| `message` | `string` | A customer-safe progress message. |
| `conditions` | `Condition[]` | The target's conditions when this progress was read. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`ETAG_MISMATCH`](/docs/api/errors/ETAG_MISMATCH) — The etag sent does not match the Resource's current etag.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/buckets/bucket:rotateCredentials" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
const operation = await sylphx.data.buckets.rotateCredentials({ name: 'orgs/acme/projects/shop/envs/production/buckets/bucket' })
```

**Rust**

```rust
let mut req = sylphx::data::RotateBucketCredentialsRequest::default();
req.name = "orgs/acme/projects/shop/envs/production/buckets/bucket".to_string();
let operation = sx.data().buckets().rotate_credentials(req).await?;
```

**CLI**

```bash
sylphx data buckets rotate-credentials orgs/acme/projects/shop/envs/production/buckets/bucket
```

**MCP**

```json
{ "method_id": "data.buckets.rotate_credentials", "args": {"name":"orgs/acme/projects/shop/envs/production/buckets/bucket"} }
```
