Skip to content

Update workspace API credential

PATCH
/v1/api-credentials/{credentialId}
curl --request PATCH \
--url https://api.dockt.com/v1/api-credentials/example \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "display_name": "example", "description": "example", "allowed_scopes": [ "account:read" ], "enabled": true }'

Updates workspace-scoped credential metadata or disables the credential.

credentialId
required

Unique Dockt API credential identifier.

string
/^cred_[A-Za-z0-9_]+$/
Media type application/json

Updates credential metadata, allowed scopes, or enabled state. Set description to null to clear it.

object
display_name
maxLength(120)

Human-readable name shown in Dockt and customer systems.

string
>= 1 characters <= 120 characters
description
Any of:
string
allowed_scopes
Array<string>
Allowed values: account:read account:write workspaces:read workspaces:write api-credentials:read api-credentials:manage features:read features:write social-compliance-packages:read workspace:read webhooks:manage assessments:read assessments:write documents:read documents:create documents:delete decisions:read decisions:outcome
enabled
boolean

Envelope for a single resource response.

Media type application/json

Envelope for a single resource response.

object
object
required
string
Allowed values: single
data
required

Machine credential metadata. Secret material is not returned after creation; store the created secret securely.

object
object
required
string
Allowed values: api_credential
id
required

Unique Dockt API credential identifier.

string
/^cred_[A-Za-z0-9_]+$/
account_id
required
Any of:

Unique Dockt account identifier.

string
/^acc_[A-Za-z0-9_]+$/
workspace_id
required
Any of:

Unique Dockt workspace identifier.

string
/^wsp_[A-Za-z0-9_]+$/
display_name
required
maxLength(120)

Human-readable name shown in Dockt and customer systems.

string
>= 1 characters <= 120 characters
description
required
Any of:
string
credential_type
required

Credential format. API keys are bearer secrets; machine-to-machine credentials use a client credential exchange.

string
Allowed values: api_key m2m
scope_type
required

Whether the credential acts across an account or only within one workspace.

string
Allowed values: account workspace
client_id
required
Any of:
minLength(1)

A string at least 1 character(s) long

string
>= 1 characters
token_url
required
Any of:

Absolute HTTP or HTTPS URI.

string format: uri
api_key_hint
required
Any of:
minLength(1)

A string at least 1 character(s) long

string
>= 1 characters
allowed_scopes
required
Array<string>
Allowed values: account:read account:write workspaces:read workspaces:write api-credentials:read api-credentials:manage features:read features:write social-compliance-packages:read workspace:read webhooks:manage assessments:read assessments:write documents:read documents:create documents:delete decisions:read decisions:outcome
enabled
required
boolean
last_used_at
required
Any of:

ISO 8601 date-time string.

string format: date-time
created_at
required

ISO 8601 date-time string.

string format: date-time
updated_at
required

ISO 8601 date-time string.

string format: date-time
Example
{
"object": "single",
"data": {
"object": "api_credential",
"account_id": "acc_example",
"workspace_id": "wsp_example",
"credential_type": "api_key",
"scope_type": "account",
"token_url": "https://example.com/webhooks/dockt",
"allowed_scopes": [
"account:read"
],
"last_used_at": "2026-08-06T09:30:00Z",
"created_at": "2026-08-06T09:30:00Z",
"updated_at": "2026-08-06T09:30:00Z"
}
}

The request did not match the expected schema

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/invalid-request",
"title": "Bad request",
"status": 400,
"detail": "The request did not match the expected schema.",
"instance": "req_example1042"
}

Problem Details response for HTTP 401. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/missing-auth",
"title": "Unauthorized",
"status": 401,
"detail": "Send a valid bearer token or browser session.",
"instance": "req_example1042"
}

Problem Details response for HTTP 403. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "The authenticated principal does not have the required permission.",
"instance": "req_example1042"
}

Problem Details response for HTTP 404. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/not-found",
"title": "Not found",
"status": 404,
"detail": "The requested resource was not found in the authenticated scope.",
"instance": "req_example1042"
}

Problem Details response for HTTP 409. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/conflict",
"title": "Conflict",
"status": 409,
"detail": "The request conflicts with the current resource state.",
"instance": "req_example1042"
}

Problem Details response for HTTP 422. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/validation",
"title": "Validation failed",
"status": 422,
"detail": "Correct the invalid fields and send the request again.",
"instance": "req_example1042",
"errors": {
"issues": [
{
"path": [
"body",
"worker",
"nationality"
],
"message": "Expected a two-letter country code."
}
]
}
}

Problem Details response for HTTP 429. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/rate-limit",
"title": "Too many requests",
"status": 429,
"detail": "Wait for the Retry-After interval before retrying.",
"instance": "req_example1042"
}

Problem Details response for HTTP 500. The type URI is the stable machine-readable error code.

Media type application/problem+json

Standard error response with a stable status, human-readable detail, and optional validation errors.

object
type
required
string
title
required
string
status
required
number
detail
required
string
instance
required
Any of:

Request identifier that Dockt support can use to trace an API call.

string
errors

Structured request validation issues.

object
issues
required
Array<object>

One request validation issue with a stable field path and human-readable message.

object
path
required
Array
message
required
string
Example
{
"type": "https://docs.dockt.com/errors/internal",
"title": "Internal server error",
"status": 500,
"detail": "Retry the request safely or contact Dockt support with the request ID.",
"instance": "req_example1042"
}