> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getmillwork.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate credential

> Rotate the connection's credential binding from a completed handoff; the current binding is kept unless the replacement passes the source test.



## OpenAPI

````yaml /openapi/solverapi.openapi.json post /v1/source-connections/{connectionId}/rotate
openapi: 3.1.0
info:
  description: >-
    Run approved AI models under data, cost, and time limits. A cost limit can
    stop another provider call after recorded spend reaches the limit; it cannot
    reverse a call already in progress. Each finished run returns a receipt
    naming the selected model and provider without including the prompt or model
    output. Use the model catalog for what your organization can run now.
    Provider secrets never appear in API requests or responses. Retry a mutation
    with the same Idempotency-Key and the same request body.
  title: Millwork API
  version: 1.0.0
servers:
  - url: https://api.getmillwork.dev
security: []
tags:
  - description: >-
      Submit work, check its status, cancel it, and read the result. The API
      calls each run an execution.
    name: Runs
  - description: A record of how a run was handled, without prompt or result content.
    name: Receipts
  - description: Models this organization can use now.
    name: Models
  - description: Providers and sign-in methods that can be connected.
    name: Available providers
  - description: Provider accounts connected to this organization.
    name: Provider connections
  - description: >-
      One-time browser steps for connecting a provider without sending its
      secret in an API request.
    name: Secure credential setup
  - description: Exact models and provider routes available through connected accounts.
    name: Provider models
  - description: Create, label, list, and revoke organization API keys.
    name: API keys
  - description: Organization members and invitations.
    name: Members
  - description: Metered usage and quota state.
    name: Usage
  - description: Account, plan and allowance snapshot.
    name: Account
  - description: Checkout, billing portal and billing profile.
    name: Billing
  - description: Webhook endpoints, deliveries and replay.
    name: Webhooks
  - description: Organization-scoped compliance export.
    name: Compliance export
  - description: >-
      Models, agents, and skills Millwork can choose for a run. The API calls
      each one an arm.
    name: Registered options
  - description: >-
      Checks that score output and can stop, retry, or choose another option
      within the request policy.
    name: Output checks
  - description: Routing proposals and their review lifecycle.
    name: Repair proposals
  - description: Aggregate evaluation trend and repair history.
    name: Evaluation
  - description: Publisher and release identity records for supported models.
    name: Model definitions
  - description: >-
      Protected provider-credential references. Secret material never appears in
      this API.
    name: Credential references
  - description: Dashboard browser sign-in, sign-up, session lookup, and sign-out.
    name: Browser access
  - description: Read-only demo session setup.
    name: Demo
  - description: Machine setup and the authenticated organization profile.
    name: Organizations
paths:
  /v1/source-connections/{connectionId}/rotate:
    post:
      tags:
        - Provider connections
      summary: Rotate credential
      description: >-
        Rotate the connection's credential binding from a completed handoff; the
        current binding is kept unless the replacement passes the source test.
      operationId: postSourceConnectionsByConnectionIdRotate
      parameters:
        - in: path
          name: connectionId
          required: true
          schema:
            maxLength: 200
            minLength: 1
            type: string
      requestBody:
        content:
          application/json:
            schema:
              additionalProperties: false
              properties:
                handoff_intent_id:
                  maxLength: 200
                  minLength: 1
                  type: string
              required:
                - handoff_intent_id
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  access_lane:
                    enum:
                      - byok
                      - millwork_pool
                    type: string
                  auth_binding_ref:
                    type: string
                  auth_scheme:
                    enum:
                      - api_key
                      - oauth2
                      - aws_sts_sigv4
                    type: string
                  binding_revision:
                    type: integer
                  commercial_owner:
                    enum:
                      - customer
                      - millwork
                    type: string
                  connection_id:
                    type: string
                  created_at:
                    format: date-time
                    type: string
                  credential_owner:
                    enum:
                      - customer
                    type: string
                  customer_ref:
                    type: string
                  display_name:
                    type: string
                  last_tested_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  revoked_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  rotated_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  source_id:
                    type: string
                  source_scope:
                    anyOf:
                      - additionalProperties: false
                        properties:
                          account_ref:
                            type: string
                          kind:
                            enum:
                              - account
                            type: string
                        required:
                          - kind
                          - account_ref
                        type: object
                      - additionalProperties: false
                        properties:
                          kind:
                            enum:
                              - project
                            type: string
                          project_ref:
                            type: string
                        required:
                          - kind
                          - project_ref
                        type: object
                      - additionalProperties: false
                        properties:
                          kind:
                            enum:
                              - region
                            type: string
                          region:
                            type: string
                        required:
                          - kind
                          - region
                        type: object
                  status:
                    enum:
                      - active
                      - disabled
                    type: string
                  test_error:
                    anyOf:
                      - enum:
                          - authentication
                          - permission
                          - model_not_found
                          - rate_limited
                          - capacity
                          - source_5xx
                        type: string
                      - type: 'null'
                  test_state:
                    enum:
                      - untested
                      - passed
                      - failed
                    type: string
                  tested_binding_revision:
                    anyOf:
                      - type: integer
                      - type: 'null'
                  updated_at:
                    format: date-time
                    type: string
                required:
                  - connection_id
                  - source_id
                  - display_name
                  - auth_scheme
                  - auth_binding_ref
                  - source_scope
                  - status
                  - access_lane
                  - credential_owner
                  - commercial_owner
                  - customer_ref
                  - binding_revision
                  - tested_binding_revision
                  - test_state
                  - test_error
                  - last_tested_at
                  - rotated_at
                  - revoked_at
                  - created_at
                  - updated_at
                type: object
          description: Default Response
        4XX:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: >-
            Request failure in RFC 7807 format. The `type` field identifies the
            reason. Validation errors list affected fields. Rate and quota
            errors include `retry_after_s` and the `Retry-After` header.
        5XX:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: >-
            Server failure in RFC 7807 format. The response does not include
            internal error details.
      security:
        - bearerAuth: []
        - sessionCookie: []
components:
  schemas:
    Problem:
      additionalProperties: false
      properties:
        detail:
          description: Short, safe, occurrence-specific description. Never a stack trace.
          type: string
        errors:
          description: Per-field validation failures (validation_failed only).
          items:
            additionalProperties: false
            properties:
              field:
                type: string
              message:
                type: string
            required:
              - field
              - message
            type: object
          type: array
        instance:
          description: Unique id for this occurrence, safe to quote in support requests.
          format: uuid
          type: string
        retry_after_s:
          description: >-
            Seconds to wait before retrying (rate_limited and quota_exceeded
            only; mirrored as the Retry-After header).
          type: integer
        status:
          description: HTTP status code, duplicated in the body per RFC 7807.
          type: integer
        title:
          description: Human-readable summary of the problem type.
          type: string
        type:
          description: Stable URI that identifies the error type.
          format: uri
          type: string
      required:
        - type
        - title
        - status
        - instance
      type: object
  securitySchemes:
    bearerAuth:
      description: Organization API key for application requests.
      scheme: bearer
      type: http
    sessionCookie:
      description: Dashboard browser session. Do not use this credential in an application.
      in: cookie
      name: solverapi_session
      type: apiKey

````