Skip to content
Start here

Update Token Configuration credentials

client.tokenValidation.configuration.credentials.update(stringconfigID, CredentialUpdateParams { zone_id, keys } params, RequestOptionsoptions?): CredentialUpdateResponse { errors, keys, messages, success }
PUT/zones/{zone_id}/token_validation/config/{config_id}/credentials

Update Token Configuration credentials with full replacement semantics. Key identities ({alg,kid}) must be unique within the request. Symmetric keys (kty: "oct") require k; k: null is invalid.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Account API GatewayDomain API Gateway
ParametersExpand Collapse
configID: string

UUID.

maxLength36
params: CredentialUpdateParams { zone_id, keys }
zone_id: string

Path param: Identifier.

maxLength32
keys: Array<APIShieldCredentialsJWTKeyRSA { alg, e, kid, 2 more } | APIShieldCredentialsJWTKeyEcEs256 { alg, crv, kid, 3 more } | APIShieldCredentialsJWTKeyEcEs384 { alg, crv, kid, 3 more } | APIShieldCredentialsJWTKeyOctRequest { alg, k, kid, kty } >

Body param

One of the following:
APIShieldCredentialsJWTKeyRSA { alg, e, kid, 2 more }

JSON representation of an RSA key.

alg: "RS256" | "RS384" | "RS512" | 3 more

Algorithm

One of the following:
"RS256"
"RS384"
"RS512"
"PS256"
"PS384"
"PS512"
e: string

RSA exponent

kid: string

Key ID

kty: "RSA"

Key Type

n: string

RSA modulus

APIShieldCredentialsJWTKeyEcEs256 { alg, crv, kid, 3 more }

JSON representation of an ES256 key

alg: "ES256"

Algorithm

crv: "P-256"

Curve

kid: string

Key ID

kty: "EC"

Key Type

x: string

X EC coordinate

y: string

Y EC coordinate

APIShieldCredentialsJWTKeyEcEs384 { alg, crv, kid, 3 more }

JSON representation of an ES384 key

alg: "ES384"

Algorithm

crv: "P-384"

Curve

kid: string

Key ID

kty: "EC"

Key Type

x: string

X EC coordinate

y: string

Y EC coordinate

APIShieldCredentialsJWTKeyOctRequest { alg, k, kid, kty }

JSON representation of a symmetric key for create/PUT requests.

alg: "HS256" | "HS384" | "HS512"

Algorithm

One of the following:
"HS256"
"HS384"
"HS512"
k: string

Symmetric key material. Required for create and PUT update requests.

kid: string

Key ID

kty: "oct"

Key Type

ReturnsExpand Collapse
CredentialUpdateResponse { errors, keys, messages, success }
errors: Message { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url?: string
source?: Source { pointer }
pointer?: string
keys: Array<APIShieldCredentialsJWTKeyRSA { alg, e, kid, 2 more } | APIShieldCredentialsJWTKeyEcEs256 { alg, crv, kid, 3 more } | APIShieldCredentialsJWTKeyEcEs384 { alg, crv, kid, 3 more } | APIShieldCredentialsJWTKeyOctResponse { alg, kid, kty } >
One of the following:
APIShieldCredentialsJWTKeyRSA { alg, e, kid, 2 more }

JSON representation of an RSA key.

alg: "RS256" | "RS384" | "RS512" | 3 more

Algorithm

One of the following:
"RS256"
"RS384"
"RS512"
"PS256"
"PS384"
"PS512"
e: string

RSA exponent

kid: string

Key ID

kty: "RSA"

Key Type

n: string

RSA modulus

APIShieldCredentialsJWTKeyEcEs256 { alg, crv, kid, 3 more }

JSON representation of an ES256 key

alg: "ES256"

Algorithm

crv: "P-256"

Curve

kid: string

Key ID

kty: "EC"

Key Type

x: string

X EC coordinate

y: string

Y EC coordinate

APIShieldCredentialsJWTKeyEcEs384 { alg, crv, kid, 3 more }

JSON representation of an ES384 key

alg: "ES384"

Algorithm

crv: "P-384"

Curve

kid: string

Key ID

kty: "EC"

Key Type

x: string

X EC coordinate

y: string

Y EC coordinate

APIShieldCredentialsJWTKeyOctResponse { alg, kid, kty }

JSON representation of a symmetric verification key in API responses (secret material is redacted).

alg: "HS256" | "HS384" | "HS512"

Algorithm

One of the following:
"HS256"
"HS384"
"HS512"
kid: string

Key ID

kty: "oct"

Key Type

messages: Message { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url?: string
source?: Source { pointer }
pointer?: string
success: true

Whether the API call was successful.

Update Token Configuration credentials

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const credential = await client.tokenValidation.configuration.credentials.update(
  '4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7',
  {
    zone_id: '023e105f4ecef8ad9ca31a8372d0c353',
    keys: [
      {
        alg: 'RS256',
        e: 'e',
        kid: 'kid',
        kty: 'RSA',
        n: 'n',
      },
    ],
  },
);

console.log(credential.errors);
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "keys": [
    {
      "alg": "ES256",
      "crv": "P-256",
      "kid": "38013f13-c266-4eec-a72a-92ec92779f21",
      "kty": "EC",
      "x": "KN53JRwN3wCjm2o39bvZUX2VdrsHzS8pxOAGjm8m7EQ",
      "y": "lnkkzIxaveggz-HFhcMWW15nxvOj0Z_uQsXbpK0GFcY"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "keys": [
    {
      "alg": "ES256",
      "crv": "P-256",
      "kid": "38013f13-c266-4eec-a72a-92ec92779f21",
      "kty": "EC",
      "x": "KN53JRwN3wCjm2o39bvZUX2VdrsHzS8pxOAGjm8m7EQ",
      "y": "lnkkzIxaveggz-HFhcMWW15nxvOj0Z_uQsXbpK0GFcY"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true
}