Partial update supported.
Switch client context (multi-tenant).
Must exist in providers table.
SMTP hostname or full HTTP URL.
SMTP port (not used for HTTP).
SMTP username.
AES-256 encrypted at rest.
HTTP provider API key; AES-256 encrypted at rest.
Only one default per client.
Route updated.
SMTP port; null for HTTP routes.
SMTP username (masked on read).
Masked value.