> ## Documentation Index
> Fetch the complete documentation index at: https://docs.interchange.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a buyer-agent API-key credential

> Replace an active buyer-agent API key while preserving its principal only when the service-token records prove a same-customer, same-workload, directly-replacing credential lineage. The request selects credential records but cannot assert identity or lineage. The replacement becomes active and the previous binding is retired atomically; retired credentials cannot be replayed.



## OpenAPI

````yaml /v2/buyer-api-v2.yaml post /buyer-agent-principals/rotate
openapi: 3.0.0
info:
  title: Scope3 Buyer API
  version: 2.0.0
  description: |-
    REST API for advertisers to manage advertisers, campaigns, and reporting.

    ## Authentication

    All endpoints require a Bearer token in the Authorization header:
    ```
    Authorization: Bearer your-api-key
    ```

    ## Base URL

    `https://api.interchange.io/api/v2/buyer`

    ## For AI Agents

    AI agents can use the MCP endpoint at `/mcp/v2/buyer` with three tools:
    - `initialize`: Start an MCP session
    - `api_call`: Make REST API calls
    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.interchange.io/api/v2/buyer
    description: Production server
security: []
tags:
  - name: Signup
    description: Request reviewed access to Interchange
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Asks
    description: >-
      What you are waiting on Scope3 for — support, product, and supply asks in
      one list
  - name: Advertisers
    description: Manage advertisers
  - name: Product Discovery
    description: Discover and select products
  - name: Campaigns
    description: Manage advertising campaigns
  - name: Creatives
    description: Build, manage, and sync campaign creatives via AdCP Creative Protocol
  - name: Reporting
    description: Access performance metrics
  - name: Event Sources
    description: >-
      Manage event source configurations and log conversion/marketing events for
      attribution
  - name: Property Lists
    description: Validate property lists against AAO registry
  - name: Sales Agents
    description: View and connect sales agents
  - name: Measurement
    description: Measurement sources, records, context, and freshness
  - name: Syndication
    description: Syndicate resources to ADCP agents
  - name: Tasks
    description: Track async operation status
  - name: Buyer Billing
    description: >-
      Consolidated invoicing for buyers — invoices and pending invoice items
      issued by Scope3 across the buyer customer.
  - name: MCP
    description: Model Context Protocol endpoints for AI agents
paths:
  /buyer-agent-principals/rotate:
    servers:
      - url: https://api.interchange.io/api/v2
        description: Production server
    post:
      tags:
        - Buyer Agent Principals
      summary: Rotate a buyer-agent API-key credential
      description: >-
        Replace an active buyer-agent API key while preserving its principal
        only when the service-token records prove a same-customer,
        same-workload, directly-replacing credential lineage. The request
        selects credential records but cannot assert identity or lineage. The
        replacement becomes active and the previous binding is retired
        atomically; retired credentials cannot be replayed.
      operationId: rotateBuyerAgentApiKeyCredential
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                type:
                  type: string
                  enum:
                    - api_key
                currentServiceTokenId:
                  type: string
                  pattern: ^[1-9][0-9]{0,18}$
                  description: >-
                    Positive PostgreSQL bigint ID as a canonical decimal string
                    (1 through 9223372036854775807).
              required:
                - type
                - currentServiceTokenId
              additionalProperties: false
              description: >-
                Rotate a registered organization-owned API key. The successor is
                server-issued with the same workload lineage.
      responses:
        '200':
          description: Rotate a buyer-agent API-key credential
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BuyerAgentCredentialRotationApiResponse'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            The caller is not a directly authenticated WorkOS organization
            administrator or a credential is outside the verified organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: The credential changed concurrently during rotation.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            Credential rotation could not be reconciled safely and must be
            retried after reconciliation.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    BuyerAgentCredentialRotationApiResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            principal:
              type: object
              properties:
                principalId:
                  type: string
                  pattern: ^prin_[A-Za-z0-9_-]{32}$
                principalKind:
                  type: string
                  enum:
                    - buyer_agent
                displayName:
                  type: string
                lifecycleState:
                  type: string
                  enum:
                    - active
                    - suspended
                    - retired
                canonicalAgentUrl:
                  type: string
                  format: uri
                authority:
                  type: object
                  properties:
                    advertiserAccountIds:
                      type: array
                      items:
                        not: {}
                    permissions:
                      type: array
                      items:
                        not: {}
                  required:
                    - advertiserAccountIds
                    - permissions
                  additionalProperties: false
                  deprecated: true
                  description: >-
                    Deprecated compatibility field; always structurally empty
                    and scheduled for removal no earlier than 2027-09-07 at the
                    next major API surface. Use access instead.
                access:
                  type: object
                  properties:
                    accessRevision:
                      type: integer
                      minimum: 0
                      maximum: 9007199254740991
                    advertisers:
                      type: array
                      items:
                        type: object
                        properties:
                          advertiserId:
                            type: string
                            pattern: ^[1-9][0-9]{0,18}$
                          name:
                            type: string
                            minLength: 1
                          role:
                            type: string
                            enum:
                              - READ
                              - READ_WRITE
                        required:
                          - advertiserId
                          - name
                          - role
                        additionalProperties: false
                  required:
                    - accessRevision
                    - advertisers
                  additionalProperties: false
              required:
                - principalId
                - principalKind
                - displayName
                - lifecycleState
                - authority
              additionalProperties: false
            credential:
              type: object
              properties:
                clientId:
                  type: string
                  minLength: 1
                clientSecret:
                  type: string
                  minLength: 1
              required:
                - clientId
                - clientSecret
              additionalProperties: false
          required:
            - principal
            - credential
          additionalProperties: false
        error:
          type: string
          nullable: true
          enum:
            - null
      required:
        - data
        - error
      additionalProperties: false
    ErrorResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
      description: Standard error response
    ApiError:
      type: object
      properties:
        code:
          type: string
          description: Machine-readable error code
        message:
          type: string
          description: Human-readable error message
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
      description: Structured error object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````