---
title: "Update Credential"
method: POST
path: "/v1/vaults/{vault_id}/credentials/{credential_id}?beta=true"
---

# Update Credential

`POST /v1/vaults/{vault_id}/credentials/{credential_id}?beta=true`

## Path parameters

- `vault_id` string, required
- `credential_id` string, required

## Headers

- `anthropic-version` string
- `anthropic-beta` string

## Request body

- BetaManagedAgentsUpdateCredentialRequestBody
  - `display_name` string, nullable — Updated human-readable name for the credential. 1-255 characters.
  - `metadata` object, nullable — Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved.
  - `auth` union — Updated authentication details for a credential.
    - object — Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable.
      - `type` 'mcp_oauth', required
      - `access_token` string, nullable — Updated OAuth access token.
      - `expires_at` string, date-time — A timestamp in RFC 3339 format
      - `refresh` BetaManagedAgentsMcpOauthRefreshUpdateParams — Parameters for updating OAuth refresh token configuration.
        - `refresh_token` string, nullable — Updated OAuth refresh token.
        - `scope` string, nullable — Updated OAuth scope for the refresh request.
        - `token_endpoint_auth` union
          - object — Updated HTTP Basic authentication parameters for the token endpoint.
            - `type` 'client_secret_basic', required
            - `client_secret` string, nullable — Updated OAuth client secret.
          - object — Updated POST body authentication parameters for the token endpoint.
            - `type` 'client_secret_post', required
            - `client_secret` string, nullable — Updated OAuth client secret.
    - object — Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable.
      - `type` 'static_bearer', required
      - `token` string, nullable — Updated static bearer token value.

## Response `200`

Successful response (OK)

- BetaManagedAgentsCredential — A credential stored in a vault. Sensitive fields are never returned in responses.
  - `type` 'vault_credential', required
  - `id` string, required — Unique identifier for the credential.
  - `vault_id` string, required — Identifier of the vault this credential belongs to.
  - `display_name` string, nullable — Human-readable name for the credential.
  - `metadata` object, required — Arbitrary key-value metadata attached to the credential.
  - `created_at` string, date-time, required — A timestamp in RFC 3339 format
  - `updated_at` string, date-time, required — A timestamp in RFC 3339 format
  - `archived_at` string, date-time, required — A timestamp in RFC 3339 format
  - `auth` union, required — Authentication details for a credential.
    - object — OAuth credential details for an MCP server.
      - `type` 'mcp_oauth', required
      - `mcp_server_url` string, required — URL of the MCP server this credential authenticates against.
      - `expires_at` string, date-time — A timestamp in RFC 3339 format
      - `refresh` BetaManagedAgentsMcpOauthRefreshResponse — OAuth refresh token configuration returned in credential responses.
        - `token_endpoint` string, required — Token endpoint URL used to refresh the access token.
        - `client_id` string, required — OAuth client ID.
        - `resource` string, nullable — OAuth resource indicator.
        - `scope` string, nullable — OAuth scope for the refresh request.
        - `token_endpoint_auth` union, required
          - object — Token endpoint requires no client authentication.
            - `type` 'none', required
          - object — Token endpoint uses HTTP Basic authentication with client credentials.
            - `type` 'client_secret_basic', required
          - object — Token endpoint uses POST body authentication with client credentials.
            - `type` 'client_secret_post', required
    - object — Static bearer token credential details for an MCP server.
      - `type` 'static_bearer', required
      - `mcp_server_url` string, required — URL of the MCP server this credential authenticates against.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time

## Changes

- **2026-04-16** `e0696f59ae07` — 1 info
  - the `auth/allOf[#/components/schemas/BetaManagedAgentsCredentialUpdateAuth]/oneOf[#/components/schemas/BetaManagedAgentsMcpOauthUpdateParams]/refresh/allOf[#/components/schemas/BetaManagedAgentsMcpOauthRefreshUpdateParams]/scope` request property's maxLength was increased from `2048` to `8192`
- **2026-04-08** `69486316563e` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/vaults/:vault_id/credentials/:credential_id?beta=true/post.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/478045ff0f4f?raw)
