> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fourdos.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate module ingest credentials

> Revokes the active credentials for the installation and returns a new raw credential once.



## OpenAPI

````yaml https://api.develop.fourdos.dev/openapi/partner.json post /v1/installations/{installationId}/credentials/rotate
openapi: 3.1.0
info:
  title: 4D OS Partner API
  version: 0.1.0
  description: >-
    REST API for 4D OS partners. Authenticate with your organization API key:
    `Authorization: Bearer <key>`.


    Requests and responses are JSON with `snake_case` field names. Errors share
    one envelope: `{ "error": { "code", "status", "message", "details"? } }`.


    Mutating endpoints that declare it accept an `Idempotency-Key` header so
    retries are safe.


    Bulk-migrating members? See the [Migrating to 4D
    guide](https://docs.fourdos.dev/walkthroughs/migrate-existing-members) for
    the canonical import schema, a worked example, and the `/v1/imports`
    sequence.
servers:
  - url: https://api.develop.fourdos.dev
security:
  - partnerApiKey: []
tags:
  - name: Users
    description: Create, read, and manage users and their org membership
  - name: Imports
    description: Bulk member import jobs (staging → validate → commit)
  - name: API keys
    description: Issue, list, and revoke server-side organization API keys
  - name: Modules
    description: >-
      Publish private modules, install visible modules, and manage their
      credentials
  - name: Ingest
    description: Receive signed native events from an installed module
  - name: Engagement
    description: Browser event tracking (publishable keys) and tracking-key management
paths:
  /v1/installations/{installationId}/credentials/rotate:
    post:
      tags:
        - Modules
      summary: Rotate module ingest credentials
      description: >-
        Revokes the active credentials for the installation and returns a new
        raw credential once.
      operationId: rotateModuleCredential
      parameters:
        - name: installationId
          in: path
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Module credential rotated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ModuleCredentialIssuedResponse'
        '401':
          description: Authentication is required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: A partner admin or platform admin session is required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Module installation not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: The module installation is disabled
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - adminSession: []
components:
  schemas:
    ModuleCredentialIssuedResponse:
      type: object
      properties:
        id:
          type: string
        module_installation_id:
          type: string
        organization_id:
          type: string
        scopes:
          type: array
          items:
            type: string
        ip_allowlist:
          type: array
          items:
            type: string
        last_used_at:
          anyOf:
            - type: string
            - type: 'null'
        rotated_at:
          anyOf:
            - type: string
            - type: 'null'
        revoked_at:
          anyOf:
            - type: string
            - type: 'null'
        created_at:
          type: string
        updated_at:
          type: string
        raw_key:
          type: string
      required:
        - id
        - module_installation_id
        - organization_id
        - scopes
        - ip_allowlist
        - last_used_at
        - rotated_at
        - revoked_at
        - created_at
        - updated_at
        - raw_key
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            status:
              type: integer
            message:
              type: string
            details:
              type: object
              additionalProperties: true
          required:
            - code
            - status
            - message
      required:
        - error
  securitySchemes:
    partnerApiKey:
      type: http
      scheme: bearer
      description: >-
        Organization API key (`org_...`) sent as `Authorization: Bearer <key>`.
        Keys are scoped to one organization; every request operates within that
        tenant.
    adminSession:
      type: http
      scheme: bearer
      description: >-
        Partner admin session token sent as `Authorization: Bearer <token>`.
        Obtained by signing in (console or the email OTP endpoints) and
        completing the second factor; see the Authentication page.

````