---
title: "PATCH /api/v1/agent-vault/access-bundles/{accessBundleId}/services/{serviceId}"
method: PATCH
path: "/api/v1/agent-vault/access-bundles/{accessBundleId}/services/{serviceId}"
tags: ["Agent Vault Access Bundles"]
---

# PATCH /api/v1/agent-vault/access-bundles/{accessBundleId}/services/{serviceId}

`PATCH /api/v1/agent-vault/access-bundles/{accessBundleId}/services/{serviceId}`

Update a service in an Agent Vault access bundle

## Path parameters

- `accessBundleId` string, uuid, required
- `serviceId` string, uuid, required

## Request body

- object
  - `name` string — The name of the service.
  - `hostPattern` string — A comma-separated set of hosts this service covers, each optionally with a port (defaults to `443`). A leading `*.` wildcard matches exactly one label. Paths are not supported.
  - `allowedMethods` string[], nullable — The HTTP methods this service allows. Null allows every method. Anything else is refused by the proxy with a 403.
  - `allowedPathPrefixes` string[], nullable — The path prefixes this service allows, matched on whole segments, so `/repos` covers `/repos/octo` but not `/repositories`. `null` allows every path. A path-restricted service also refuses any request whose path would have to be normalised to judge.
  - `credential` union
    - object
      - `type` 'bearer', required
      - `headerName` string — The header the credential is written to. Defaults to `Authorization`.
      - `headerPrefix` string — Written before the credential value, separated by one space. Leave empty for a header that carries the value alone, such as DD-API-KEY. Can't contain `{{` or `}}`. On update a field left out keeps its stored value, so send an empty string to clear the prefix when changing the header.
      - `value` string — The secret. Can use up to 3 references to the access bundle's variables, written as `{{KEY}}`. A reference that repeats counts each time. Omit to keep the stored secret.
    - object
      - `type` 'basic', required
      - `username` string — The username half of the basic credential. Can use up to 3 references to the access bundle's variables, written as `{{KEY}}`. A reference that repeats counts each time. Omit to keep the stored username; send an empty string to remove it, which requires a password.
      - `password` string — The password half of the basic credential. Can use up to 3 references to the access bundle's variables, written as `{{KEY}}`. A reference that repeats counts each time. Omit to keep the stored password; send an empty string to remove it, which requires a username.
    - object
      - `type` 'passthrough', required
  - `customHeaders` object[] — Additional headers the proxy attaches to every request to this service, on top of the credential. Send the full list. A header you leave out is deleted. Send a header's `id` to change it in place and keep its stored value. Without an `id`, a header is matched by name.
    - `id` string, uuid — The ID of the custom header. Send it to change that header in place. Omit it to match by name.
    - `name` string, required — The name of the header, which must not be the credential's own header.
    - `prefix` string — Written before the header value, separated by one space. Can't contain `{{` or `}}`. Unlike the value, an omitted prefix is cleared rather than kept, since the stored prefix is returned and can be resent.
    - `value` string — The header value. Can use up to 3 references to the access bundle's variables, written as `{{KEY}}`. A reference that repeats counts each time. Omit to keep the value already stored for this header.
  - `substitutions` object[] — Placeholders the proxy swaps for a real secret before forwarding. Send the full list. A substitution you leave out is deleted. Send a substitution's `id` to change it in place and keep its stored value. Without an `id`, it is matched by its placeholder.
    - `id` string, uuid — The ID of the substitution. Send it to change that substitution in place. Omit it to match by placeholder.
    - `placeholder` string, required — The fake value your agent already sends. The proxy replaces it with the real secret. Matched as a plain string, so a distinctive placeholder is worth choosing. Can't contain `{{` or `}}`.
    - `surfaces` string[], required — Where in the request to look for the placeholder: path, query, header or body.
    - `value` string — The real value the placeholder is replaced with. Can use up to 3 references to the access bundle's variables, written as `{{KEY}}`. A reference that repeats counts each time. Omit to keep the value already stored.

## Response `200`

Default Response

- object
  - `service` object, required
    - `id` string, uuid, required — The ID of the service.
    - `accessBundleId` string, uuid, required — The ID of the access bundle.
    - `name` string, required — The name of the service.
    - `hostPattern` string, required — A comma-separated set of hosts this service covers, each optionally with a port (defaults to `443`). A leading `*.` wildcard matches exactly one label. Paths are not supported.
    - `allowedMethods` string[], nullable, required — The HTTP methods this service allows. Null allows every method. Anything else is refused by the proxy with a 403.
    - `allowedPathPrefixes` string[], nullable, required — The path prefixes this service allows, matched on whole segments, so `/repos` covers `/repos/octo` but not `/repositories`. `null` allows every path. A path-restricted service also refuses any request whose path would have to be normalised to judge.
    - `credential` union, required
      - object
        - `type` 'bearer', required
        - `headerName` string, required — The header the credential is written to. Defaults to `Authorization`.
        - `headerPrefix` string, required — Written before the credential value, separated by one space. Leave empty for a header that carries the value alone, such as DD-API-KEY. Can't contain `{{` or `}}`. On update a field left out keeps its stored value, so send an empty string to clear the prefix when changing the header.
      - object
        - `type` 'basic', required
      - object
        - `type` 'passthrough', required
    - `customHeaders` object[], required — Additional headers the proxy attaches to every request to this service, on top of the credential. Send the full list. A header you leave out is deleted. Send a header's `id` to change it in place and keep its stored value. Without an `id`, a header is matched by name.
      - `id` string, uuid, required — The ID of the custom header. Send it to change that header in place. Omit it to match by name.
      - `name` string, required — The name of the header, which must not be the credential's own header.
      - `prefix` string, required — Written before the header value, separated by one space. Leave empty to send the value alone. Can't contain `{{` or `}}`.
    - `substitutions` object[], required — Placeholders the proxy swaps for a real secret before forwarding. Send the full list. A substitution you leave out is deleted. Send a substitution's `id` to change it in place and keep its stored value. Without an `id`, it is matched by its placeholder.
      - `id` string, uuid, required — The ID of the substitution. Send it to change that substitution in place. Omit it to match by placeholder.
      - `placeholder` string, required — The fake value your agent already sends. The proxy replaces it with the real secret. Matched as a plain string, so a distinctive placeholder is worth choosing. Can't contain `{{` or `}}`.
      - `surfaces` string[], required — Where in the request to look for the placeholder: path, query, header or body.
    - `variableReferences` union[], required — The variables this service's credential, custom header values and substitution values use. Not returned to Agent Vault members, since only admins can see variables.
      - union
        - object
          - `variableId` string, uuid, required — The ID of the variable.
          - `key` string, required — The name services use to refer to the variable, as `{{KEY}}`. Starts with a letter and uses only upper case letters, numbers and underscores.
          - `field` 'credential-value' | 'credential-username', required — Which value uses the variable: credential-value (a bearer token or a basic password), credential-username, custom-header or substitution.
        - object
          - `variableId` string, uuid, required — The ID of the variable.
          - `key` string, required — The name services use to refer to the variable, as `{{KEY}}`. Starts with a letter and uses only upper case letters, numbers and underscores.
          - `field` 'custom-header', required — Which value uses the variable: credential-value (a bearer token or a basic password), credential-username, custom-header or substitution.
          - `customHeaderId` string, uuid, required — The custom header whose value uses the variable.
        - object
          - `variableId` string, uuid, required — The ID of the variable.
          - `key` string, required — The name services use to refer to the variable, as `{{KEY}}`. Starts with a letter and uses only upper case letters, numbers and underscores.
          - `field` 'substitution', required — Which value uses the variable: credential-value (a bearer token or a basic password), credential-username, custom-header or substitution.
          - `substitutionId` string, uuid, required — The substitution whose value uses the variable.
    - `createdAt` string, date-time, required — When the service was added to the access bundle.
    - `updatedAt` string, date-time, required — When the service was last changed.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-10-01** `8d8e9d059648` — 1 info
  - added the required property `service/variableReferences` to the response with the `200` status
- **2026-09-22** `62b0ba9edfe9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/access-bundles/:accessBundleId/services/:serviceId/patch.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/8d8e9d059648?raw)
