Start Secret Rotation - Stytch Docs
Documentation Index
Fetch the complete documentation index at: /docs/llms.txt
Use this file to discover all available pages before exploring further.
C# Example
// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
const stytch = require('stytch');
const client = new stytch.B2BClient({
project_id: '${projectId}',
secret: '${secret}',
});
const params = {
client_id: "m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
};
client.M2M.Clients.Secrets.RotateStart(params)
.then(resp => { console.log(resp) })
.catch(err => { console.log(err) });
Go Example
// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
package main
import (
"context"
"log"
"github.com/stytchauth/stytch-go/v18/stytch/b2b/b2bstytchapi"
"github.com/stytchauth/stytch-go/v18/stytch/consumer/m2m/clients/secrets"
)
func main() {
client, err := b2bstytchapi.NewClient(
"${projectId}",
"${secret}",
)
if err != nil {
log.Fatalf("error instantiating client: %v", err)
}
params := &secrets.RotateStartParams{
ClientID: "m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
}
resp, err := client.M2M.Clients.Secrets.RotateStart(context.Background(), params)
if err != nil {
log.Fatalf("error in method call: %v", err)
}
log.Println(resp)
}
Java Example
// POST /v1/m2m/clients/{client_id}/secrets/rotate/start
package com.example;
import com.stytch.java.b2b.StytchB2BClient;
import com.stytch.java.common.StytchResult;
import com.stytch.java.consumer.models.m2mclientssecrets.RotateStartRequest;
public class Main {
public static void main(String[] args) {
StytchB2BClient.configure("${projectId}", "${secret}");
RotateStartRequest params = new RotateStartRequest();
params.setClientId("m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885");
Object result = StytchB2BClient.getM2M().getClients().getSecrets().rotateStart(params);
if (result instanceof StytchResult.Success) {
System.out.println(((StytchResult.Success) result).getValue());
} else {
System.out.println(((StytchResult.Error) result).getException());
}
}
}
Python Example
# POST /v1/m2m/clients/{client_id}/secrets/rotate/start
from stytch import B2BClient
client = B2BClient(
project_id="${projectId}",
secret="${secret}",
)
resp = client.m2m.clients.secrets.rotate_start(
client_id="m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885",
)
print(resp)
Curl Example
# POST /v1/m2m/clients/{client_id}/secrets/rotate/start
curl --request POST \
--url https://test.stytch.com/v1/m2m/clients/m2m-client-test-d731954d-dab3-4a2b-bdee-07f3ad1be885/secrets/rotate/start \
-u '${projectId}:${secret}' \
-H 'Content-Type: application/json'
Responses
Successful Response
{
"request_id": "<string>",
"m2m_client": {
"client_id": "<string>",
"next_client_secret": "<string>",
"client_name": "<string>",
"client_description": "<string>",
"status": "<string>",
"scopes": [
"<string>"
],
"client_secret_last_four": "<string>",
"trusted_metadata": {},
"next_client_secret_last_four": "<string>"
},
"status_code": 123
}
Error Responses
401 Unauthorized
{
"status_code": 401,
"request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
"error_type": "unauthorized_credentials",
"error_message": "Unauthorized credentials.",
"error_url": "https://stytch.com/docs/api/errors/401"
}
429 Too Many Requests
{
"status_code": 429,
"request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
"error_type": "too_many_requests",
"error_message": "Too many requests have been made.",
"error_url": "https://stytch.com/docs/api/errors/429"
}
500 Internal Server Error
{
"status_code": 500,
"request_id": "request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141",
"error_type": "internal_server_error",
"error_message": "Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong.",
"error_url": "https://stytch.com/docs/api/errors/500"
}
After this endpoint is called, both the client’s client_secret and next_client_secret will be valid. To complete the secret rotation flow, update all usages of client_secret to next_client_secret and call the Rotate Secret Endpoint to complete the flow. Secret rotation can be cancelled using the Rotate Cancel Endpoint.
The API response is the only time you will be able to view the generated next_client_secret. Stytch stores a hash of the next_client_secret and cannot recover the value if lost. Be sure to persist the next_client_secret in a secure location. If the next_client_secret is lost, you will need to trigger a secret rotation flow to receive another one.
Authorizations
Authorization required: Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Path Parameters
- client_id: string, required - The ID of the client.