> ## Documentation Index
> Fetch the complete documentation index at: https://docs.interchange.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate messaging app credentials

> Atomically replace the provider credential for an active messaging app. The replacement is stored before the reference swap, the previous secret is detached afterward, and no credential value is returned.



## OpenAPI

````yaml /v2/buyer-api-v2.yaml put /messaging-apps/{definitionId}/credentials
openapi: 3.0.0
info:
  title: Scope3 Buyer API
  version: 2.0.0
  description: |-
    REST API for advertisers to manage advertisers, campaigns, and reporting.

    ## Authentication

    All endpoints require a Bearer token in the Authorization header:
    ```
    Authorization: Bearer your-api-key
    ```

    ## Base URL

    `https://api.interchange.io/api/v2/buyer`

    ## For AI Agents

    AI agents can use the MCP endpoint at `/mcp/v2/buyer` with three tools:
    - `initialize`: Start an MCP session
    - `api_call`: Make REST API calls
    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.interchange.io/api/v2/buyer
    description: Production server
security: []
tags:
  - name: Signup
    description: Request reviewed access to Interchange
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Asks
    description: >-
      What you are waiting on Scope3 for — support, product, and supply asks in
      one list
  - name: Advertisers
    description: Manage advertisers
  - name: Product Discovery
    description: Discover and select products
  - name: Campaigns
    description: Manage advertising campaigns
  - name: Creatives
    description: Build, manage, and sync campaign creatives via AdCP Creative Protocol
  - name: Reporting
    description: Access performance metrics
  - name: Event Sources
    description: >-
      Manage event source configurations and log conversion/marketing events for
      attribution
  - name: Property Lists
    description: Validate property lists against AAO registry
  - name: Sales Agents
    description: View and connect sales agents
  - name: Measurement
    description: Measurement sources, records, context, and freshness
  - name: Syndication
    description: Syndicate resources to ADCP agents
  - name: Tasks
    description: Track async operation status
  - name: Buyer Billing
    description: >-
      Consolidated invoicing for buyers — invoices and pending invoice items
      issued by Scope3 across the buyer customer.
  - name: MCP
    description: Model Context Protocol endpoints for AI agents
paths:
  /messaging-apps/{definitionId}/credentials:
    servers:
      - url: https://api.interchange.io/api/v2
        description: Production server
    put:
      tags:
        - Account
      summary: Rotate messaging app credentials
      description: >-
        Atomically replace the provider credential for an active messaging app.
        The replacement is stored before the reference swap, the previous secret
        is detached afterward, and no credential value is returned.
      operationId: rotateMessagingAppCredential
      parameters:
        - in: path
          name: definitionId
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              oneOf:
                - type: object
                  properties:
                    provider:
                      type: string
                      enum:
                        - discord
                    publicKey:
                      type: string
                      pattern: ^[0-9a-f]{64}$
                    botToken:
                      type: string
                      minLength: 32
                      maxLength: 2048
                  required:
                    - provider
                    - publicKey
                    - botToken
                  additionalProperties: false
                - type: object
                  properties:
                    provider:
                      type: string
                      enum:
                        - teams
                    applicationTenantId:
                      anyOf:
                        - type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        - type: string
                          enum:
                            - organizations
                    clientSecret:
                      type: string
                      minLength: 16
                      maxLength: 4096
                  required:
                    - provider
                    - applicationTenantId
                    - clientSecret
                  additionalProperties: false
                - type: object
                  properties:
                    provider:
                      type: string
                      enum:
                        - whatsapp
                    appSecret:
                      type: string
                      minLength: 16
                      maxLength: 4096
                    accessToken:
                      type: string
                      minLength: 32
                      maxLength: 8192
                    webhookVerifyToken:
                      type: string
                      minLength: 32
                      maxLength: 512
                    graphApiVersion:
                      type: string
                      pattern: ^v\d{1,2}\.\d$
                  required:
                    - provider
                    - appSecret
                    - accessToken
                    - webhookVerifyToken
                    - graphApiVersion
                  additionalProperties: false
              type: object
      responses:
        '200':
          description: Rotate messaging app credentials
          content:
            application/json:
              schema:
                type: object
                properties:
                  definition:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      customerId:
                        type: integer
                        minimum: 0
                        exclusiveMinimum: true
                        maximum: 9007199254740991
                      agentKey:
                        type: string
                        minLength: 1
                        maxLength: 128
                      brand:
                        type: object
                        properties:
                          displayName:
                            type: string
                            minLength: 1
                            maxLength: 80
                          shortDescription:
                            type: string
                            minLength: 1
                            maxLength: 200
                          accentColor:
                            type: string
                            pattern: ^#[0-9a-f]{6}$
                          iconAssetId:
                            type: string
                            format: uuid
                            pattern: >-
                              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                          supportUrl:
                            type: string
                            format: uri
                            pattern: ^https:\/\/.*
                          privacyPolicyUrl:
                            type: string
                            format: uri
                            pattern: ^https:\/\/.*
                          termsUrl:
                            type: string
                            format: uri
                            pattern: ^https:\/\/.*
                        required:
                          - displayName
                          - supportUrl
                          - privacyPolicyUrl
                        additionalProperties: false
                      providerRef:
                        oneOf:
                          - type: object
                            properties:
                              provider:
                                type: string
                                enum:
                                  - slack
                              applicationId:
                                type: string
                                minLength: 1
                                maxLength: 2048
                            required:
                              - provider
                              - applicationId
                            additionalProperties: false
                          - type: object
                            properties:
                              provider:
                                type: string
                                enum:
                                  - teams
                              applicationId:
                                type: string
                                minLength: 1
                                maxLength: 2048
                            required:
                              - provider
                              - applicationId
                            additionalProperties: false
                          - type: object
                            properties:
                              provider:
                                type: string
                                enum:
                                  - discord
                              applicationId:
                                type: string
                                minLength: 1
                                maxLength: 2048
                            required:
                              - provider
                              - applicationId
                            additionalProperties: false
                          - type: object
                            properties:
                              provider:
                                type: string
                                enum:
                                  - whatsapp
                              businessAccountId:
                                type: string
                                minLength: 1
                                maxLength: 2048
                              phoneNumberId:
                                type: string
                                minLength: 1
                                maxLength: 2048
                            required:
                              - provider
                              - businessAccountId
                              - phoneNumberId
                            additionalProperties: false
                        type: object
                      status:
                        type: string
                        enum:
                          - draft
                          - active
                          - retired
                    required:
                      - id
                      - customerId
                      - agentKey
                      - brand
                      - providerRef
                      - status
                    additionalProperties: false
                  rotated:
                    type: boolean
                    enum:
                      - true
                required:
                  - definition
                  - rotated
                additionalProperties: false
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Active organization admin required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Active app definition not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
      description: Standard error response
    ApiError:
      type: object
      properties:
        code:
          type: string
          description: Machine-readable error code
        message:
          type: string
          description: Human-readable error message
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
      description: Structured error object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````