Start Secret Rotation - Stytch Docs

Documentation Index

Fetch the complete documentation index at: /docs/llms.txt

Use this file to discover all available pages before exploring further.

C# Example

// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
const stytch = require('stytch');

const client = new stytch.B2BClient({
  project_id: '${projectId}',
  secret: '${secret}',
});

const params = {
  client_id: "m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
};

client.M2M.Clients.Secrets.RotateStart(params)
  .then(resp => { console.log(resp) })
  .catch(err => { console.log(err) });

Go Example

// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
package main

import (
    "context"
    "log"

"github.com/stytchauth/stytch-go/v18/stytch/b2b/b2bstytchapi"
    "github.com/stytchauth/stytch-go/v18/stytch/consumer/m2m/clients/secrets"
)

func main() {
    client, err := b2bstytchapi.NewClient(
        "${projectId}",
        "${secret}",
    )
    if err != nil {
        log.Fatalf("error instantiating client: %v", err)
    }

params := &secrets.RotateStartParams{
        ClientID: "m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
    }

resp, err := client.M2M.Clients.Secrets.RotateStart(context.Background(), params)
    if err != nil {
        log.Fatalf("error in method call: %v", err)
    }

log.Println(resp)
}

Java Example

// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
package com.example;

import com.stytch.java.b2b.StytchB2BClient;
import com.stytch.java.common.StytchResult;
import com.stytch.java.consumer.models.m2mclientssecrets.RotateStartRequest;

public class Main {
    public static void main(String[] args) {
        StytchB2BClient.configure("${projectId}", "${secret}");

RotateStartRequest params = new RotateStartRequest();
        params.setClientId("m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885");

Object result = StytchB2BClient.getM2M().getClients().getSecrets().rotateStart(params);
        if (result instanceof StytchResult.Success) {
          System.out.println(((StytchResult.Success) result).getValue());
        } else {
          System.out.println(((StytchResult.Error) result).getException());
        }
    }
}

Python Example

# POST /v1/m2m/clients/{client_id}/secrets/rotate/start
from stytch import B2BClient

client = B2BClient(
    project_id="${projectId}",
    secret="${secret}",
)

resp = client.m2m.clients.secrets.rotate_start(
    client_id="m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
)

print(resp)

Curl Example

# POST /v1/m2m/clients/{client_id}/secrets/rotate/start
curl --request POST \
  --url https://test.stytch.com/v1/m2m/clients/m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885/secrets/rotate/start \
  -u '${projectId}:${secret}' \
  -H 'Content-Type: application/json'

Responses

Successful Response

{
  "request_id": "<string>",
  "m2m_client": {
    "client_id": "<string>",
    "next_client_secret": "<string>",
    "client_name": "<string>",
    "client_description": "<string>",
    "status": "<string>",
    "scopes": [
      "<string>"
    ],
    "client_secret_last_four": "<string>",
    "trusted_metadata": {},
    "next_client_secret_last_four": "<string>"
  },
  "status_code": 123
}

Error Responses

401 Unauthorized
{
  "status_code": 401,
  "request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
  "error_type": "unauthorized_credentials",
  "error_message": "Unauthorized credentials.",
  "error_url": "https://stytch.com/docs/api/errors/401"
}
429 Too Many Requests
{
  "status_code": 429,
  "request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
  "error_type": "too_many_requests",
  "error_message": "Too many requests have been made.",
  "error_url": "https://stytch.com/docs/api/errors/429"
}
500 Internal Server Error
{
  "status_code": 500,
  "request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
  "error_type": "internal_server_error",
  "error_message": "Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong.",
  "error_url": "https://stytch.com/docs/api/errors/500"
}

After this endpoint is called, both the client’s client_secret and next_client_secret will be valid. To complete the secret rotation flow, update all usages of client_secret to next_client_secret and call the Rotate Secret Endpoint to complete the flow. Secret rotation can be cancelled using the Rotate Cancel Endpoint.

The API response is the only time you will be able to view the generated next_client_secret. Stytch stores a hash of the next_client_secret and cannot recover the value if lost. Be sure to persist the next_client_secret in a secure location. If the next_client_secret is lost, you will need to trigger a secret rotation flow to receive another one.

Authorizations

Authorization required: Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Path Parameters