---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Update a store connection"
description: "`money.store_connections.update` (PATCH /v1/{store_connection.name}): Updates a store connection; a new credential replaces the stored one."
type: reference
product: purchases
summary: "Updates a store connection; a new credential replaces the stored one."
updated: 2026-09-28
nav: false
---

Updates a store connection; a new credential replaces the stored one.

- **Path** `PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections/store-connection`
- **Scope** `billing:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [store_connections](/docs/api/store_connections)
- **Query** `update_mask`, `allow_missing`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `store_connection` | `StoreConnection` | The store connection to update; `name` identifies it. Required. |
| `update_mask` | `field_mask` | The fields to write; unset writes every populated field. |
| `allow_missing` | `bool` | Create the store connection when it does not exist (declarative upsert). |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### StoreConnection

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/store_connections/{store_connection}`; by convention `app-store` or `google-play`. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `StoreConnectionSpec` | Desired state. Required. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

### StoreConnectionSpec

| Field | Type | What it is |
| --- | --- | --- |
| `app_store` | `AppStoreConnection` | The App Store. One of the `store` group. |
| `google_play` | `GooglePlayConnection` | Google Play. One of the `store` group. |
| `allow_sandbox` | `bool` | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
| `require_account_token` | `bool` | Refuse a purchase that does not carry the subject's account token (App Store `appAccountToken`, Play `obfuscatedAccountId`). |

### AppStoreConnection

| Field | Type | What it is |
| --- | --- | --- |
| `bundle_ids` | `string[]` | The apps' bundle ids. Required. |
| `issuer_id` | `string` | The App Store Connect issuer id. Required. |
| `key_id` | `string` | The In-App Purchase key id. Required. |
| `private_key` | `string` | The In-App Purchase key (`.p8` PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
| `app_apple_id` | `int64` | The app's Apple id, needed to verify production notifications. |
| `account_token_prefix` | `string` | An earlier `appAccountToken` scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example `https://accounts.example.com/v2/`). Tokens in Money's own scheme are always accepted as well. |

### GooglePlayConnection

| Field | Type | What it is |
| --- | --- | --- |
| `package_names` | `string[]` | The apps' package names. Required. |
| `service_account_json` | `string` | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
| `notification_audience` | `string` | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
| `notification_service_account` | `string` | The service account Pub/Sub pushes as. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/store_connections/{store_connection}`; by convention `app-store` or `google-play`. |
| `uid` | `string` | `stc_<cell><ulid>`; never reused. Store notifications for this connection are sent to a URL that carries it. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `StoreConnectionSpec` | Desired state. Required. |
| `status` | `StoreConnectionStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### StoreConnectionSpec

| Field | Type | What it is |
| --- | --- | --- |
| `app_store` | `AppStoreConnection` | The App Store. One of the `store` group. |
| `google_play` | `GooglePlayConnection` | Google Play. One of the `store` group. |
| `allow_sandbox` | `bool` | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
| `require_account_token` | `bool` | Refuse a purchase that does not carry the subject's account token (App Store `appAccountToken`, Play `obfuscatedAccountId`). |

### StoreConnectionStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready when a credential is stored. Output only. |
| `credential_set` | `bool` | Whether a credential is stored. Output only. |
| `notification_url` | `string` | Where the store sends its notifications for this connection. Output only. |
| `service_account_email` | `string` | The service account's email, read from the stored key (Play only). Output only. |

### AppStoreConnection

| Field | Type | What it is |
| --- | --- | --- |
| `bundle_ids` | `string[]` | The apps' bundle ids. Required. |
| `issuer_id` | `string` | The App Store Connect issuer id. Required. |
| `key_id` | `string` | The In-App Purchase key id. Required. |
| `private_key` | `string` | The In-App Purchase key (`.p8` PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
| `app_apple_id` | `int64` | The app's Apple id, needed to verify production notifications. |
| `account_token_prefix` | `string` | An earlier `appAccountToken` scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example `https://accounts.example.com/v2/`). Tokens in Money's own scheme are always accepted as well. |

### GooglePlayConnection

| Field | Type | What it is |
| --- | --- | --- |
| `package_names` | `string[]` | The apps' package names. Required. |
| `service_account_json` | `string` | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
| `notification_audience` | `string` | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
| `notification_service_account` | `string` | The service account Pub/Sub pushes as. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`ETAG_MISMATCH`](/docs/api/errors/ETAG_MISMATCH) — The etag sent does not match the Resource's current etag.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X PATCH "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections/store-connection" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"orgs/acme/projects/shop/envs/production/store_connections/store-connection","spec":{}}'
```

**TypeScript**

```ts
const response = await sylphx.money.storeConnections.update({ storeConnection: { name: 'orgs/acme/projects/shop/envs/production/store_connections/store-connection', spec: {} } })
```

**Rust**

```rust
let mut req = sylphx::money::UpdateStoreConnectionRequest::default();
req.store_connection = Some(sylphx::money::StoreConnection {
    name: "orgs/acme/projects/shop/envs/production/store_connections/store-connection".to_string(),
    spec: Some(Default::default()),
    ..Default::default()
});
let response = sx.money().store_connections().update(req).await?;
```

**CLI**

```bash
sylphx money store-connections update orgs/acme/projects/shop/envs/production/store_connections/store-connection
```

**MCP**

```json
{ "method_id": "money.store_connections.update", "args": {"store_connection":{"name":"orgs/acme/projects/shop/envs/production/store_connections/store-connection","spec":{}}} }
```
