---
title: "PATCH /api/v1/pki/syncs/gcp-certificate-manager/{pkiSyncId}"
method: PATCH
path: "/api/v1/pki/syncs/gcp-certificate-manager/{pkiSyncId}"
tags: ["PKI Syncs"]
---

# PATCH /api/v1/pki/syncs/gcp-certificate-manager/{pkiSyncId}

`PATCH /api/v1/pki/syncs/gcp-certificate-manager/{pkiSyncId}`

Update the specified GCP Certificate Manager PKI Sync.

## Path parameters

- `pkiSyncId` string, required

## Request body

- object
  - `name` string
  - `description` string
  - `isAutoSyncEnabled` boolean
  - `destinationConfig` object
    - `gcpProjectId` string, required
    - `location` string, required
    - `certificateMapBinding` object
      - `certificateMap` string, required
      - `hostname` string
    - `scope` 'default' | 'edge-cache' | 'all-regions' | 'client-auth'
  - `syncOptions` object
    - `canRemoveCertificates` boolean
    - `includeRootCa` boolean
    - `preserveItemOnRenewal` boolean
    - `healthCheckCommand` string, nullable
    - `canImportCertificates` false
    - `labels` object[]
      - `key` string, required
      - `value` string, required
    - `certificateNameSchema` string, required
  - `subscriberId` string, nullable
  - `connectionId` string, uuid
  - `filters` object, nullable — Replaces which of the Application's certificates this sync holds. Omit to leave them unchanged, or set to null to empty the sync.
    - `profileIds` string[] — Match certificates issued from any one of these certificate profiles.
    - `certificateOrderIds` string[] — Match any certificate belonging to any one of these certificate orders. An order groups a certificate with every renewal of it, so this keeps matching as the certificate is renewed.
    - `metadata` object[] — Match certificates carrying every one of these metadata pairs. Give a key on its own to match any value for that key.
      - `key` string, required — Metadata key the certificate must carry.
      - `value` string — Metadata value the key must have. Omit it to match any value.

## Response `200`

Default Response

- object
  - `id` string, uuid, required
  - `name` string, required
  - `description` string, nullable
  - `destination` 'gcp-certificate-manager', required
  - `isAutoSyncEnabled` boolean, required
  - `destinationConfig` object, required
    - `gcpProjectId` string, required
    - `location` string, required
    - `certificateMapBinding` object
      - `certificateMap` string, required
      - `hostname` string
    - `scope` 'default' | 'edge-cache' | 'all-regions' | 'client-auth'
  - `syncOptions` object, required
    - `canRemoveCertificates` boolean
    - `includeRootCa` boolean
    - `preserveItemOnRenewal` boolean
    - `healthCheckCommand` string, nullable
    - `canImportCertificates` false
    - `labels` object[]
      - `key` string, required
      - `value` string, required
    - `certificateNameSchema` string, required
  - `projectId` string, uuid, required
  - `subscriberId` string, uuid, nullable
  - `connectionId` string, uuid, required
  - `createdAt` string, date-time, required
  - `updatedAt` string, date-time, required
  - `syncStatus` string, nullable
  - `lastSyncedAt` string, date-time, nullable
  - `lastHealthCheckRanAt` string, date-time, nullable
  - `lastHealthCheckStatus` 'pending' | 'running' | 'succeeded' | 'failed', nullable
  - `lastHealthCheckMessage` string, nullable
  - `filters` object, nullable — Which of the Application's certificates this sync holds. A certificate must match every field that is set, and a sync with no filters holds nothing.
    - `profileIds` string[]
    - `certificateOrderIds` string[]
    - `metadata` object[]
      - `key` string, required
      - `value` string

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-17** `7a0c98551644` — 2 info
  - added the new optional request property `filters`
  - added the optional property `filters` to the response with the `200` status
- **2026-08-28** `c339fd54e42e` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/pki/syncs/gcp-certificate-manager/:pkiSyncId/patch.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/3f1f969fcbcb?raw)
