> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberdesk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Upsert Provider Credential

> Add or replace the organization's credential for a provider slot.

Once a slot has a credential, Cyberdesk stops using its own keys for that provider.



## OpenAPI

````yaml /openapi.json put /v1/provider-credentials/{slot}
openapi: 3.1.0
info:
  title: Cyberdesk Cloud
  description: >-
    The Cyberdesk API provides programmatic access to all platform features,
    enabling you to automate desktop tasks at scale.
  version: 1.0.0
servers:
  - url: https://api.cyberdesk.io
    description: Production server
  - url: https://cyberdesk-api-dev.fly.dev
    description: Development server
security: []
paths:
  /v1/provider-credentials/{slot}:
    put:
      tags:
        - provider-credentials
      summary: Upsert Provider Credential
      description: >-
        Add or replace the organization's credential for a provider slot.


        Once a slot has a credential, Cyberdesk stops using its own keys for
        that provider.
      operationId: upsert_provider_credential_v1_provider_credentials__slot__put
      parameters:
        - name: slot
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/ProviderCredentialSlot'
        - name: Idempotency-Key
          in: header
          required: false
          description: >-
            Unique key for idempotent requests. If provided, the server ensures
            the request is processed at most once. Retries with the same key
            return the original response. SDKs auto-generate this for write
            requests.
          schema:
            type: string
            example: 550e8400-e29b-41d4-a716-446655440000
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProviderCredentialUpsert'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProviderCredentialResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - HTTPBearer: []
components:
  schemas:
    ProviderCredentialSlot:
      type: string
      enum:
        - anthropic
        - openai
        - google
        - aws_bedrock
      title: ProviderCredentialSlot
    ProviderCredentialUpsert:
      properties:
        api_key:
          anyOf:
            - type: string
            - type: 'null'
          title: Api Key
          description: >-
            API key for the anthropic/openai slots, or the Bedrock API key when
            bedrock_auth_mode=api_key.
        service_account_json:
          anyOf:
            - type: string
            - type: 'null'
          title: Service Account Json
          description: >-
            Google Cloud service account key file contents (JSON string) for the
            google slot.
        bedrock_auth_mode:
          anyOf:
            - $ref: '#/components/schemas/BedrockAuthMode'
            - type: 'null'
          description: >-
            AWS Bedrock authentication mode: 'api_key' (Bedrock API key) or
            'iam' (access key pair).
        aws_access_key_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Aws Access Key Id
        aws_secret_access_key:
          anyOf:
            - type: string
            - type: 'null'
          title: Aws Secret Access Key
        aws_region:
          anyOf:
            - type: string
            - type: 'null'
          title: Aws Region
          description: 'AWS region for Bedrock. One of: us-east-1, us-east-2, us-west-2.'
      additionalProperties: false
      type: object
      title: ProviderCredentialUpsert
      description: >-
        Credential material for one slot. Which fields are required depends on
        the slot.
    ProviderCredentialResponse:
      properties:
        slot:
          $ref: '#/components/schemas/ProviderCredentialSlot'
        display_name:
          type: string
          title: Display Name
        source:
          $ref: '#/components/schemas/ProviderCredentialSource'
          description: >-
            'cyberdesk' when the slot has never been configured (Cyberdesk
            platform keys are used).
        covered_providers:
          items:
            type: string
          type: array
          title: Covered Providers
        status:
          anyOf:
            - $ref: '#/components/schemas/ProviderCredentialStatus'
            - type: 'null'
        auth_type:
          anyOf:
            - $ref: '#/components/schemas/ProviderCredentialAuthType'
            - type: 'null'
        display_metadata:
          $ref: '#/components/schemas/ProviderCredentialDisplayMetadata'
        last_error:
          anyOf:
            - type: string
            - type: 'null'
          title: Last Error
        activated_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Activated At
        last_validated_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Last Validated At
        created_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Created At
        updated_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Updated At
      type: object
      required:
        - slot
        - display_name
        - source
        - covered_providers
      title: ProviderCredentialResponse
      description: State of one BYOK slot. Never includes secret material.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    BedrockAuthMode:
      type: string
      enum:
        - api_key
        - iam
      title: BedrockAuthMode
    ProviderCredentialSource:
      type: string
      enum:
        - cyberdesk
        - organization
      title: ProviderCredentialSource
    ProviderCredentialStatus:
      type: string
      enum:
        - active
        - invalid
        - missing
      title: ProviderCredentialStatus
    ProviderCredentialAuthType:
      type: string
      enum:
        - api_key
        - service_account_json
        - aws_bedrock_api_key
        - aws_iam
      title: ProviderCredentialAuthType
    ProviderCredentialDisplayMetadata:
      properties:
        key_last4:
          anyOf:
            - type: string
            - type: 'null'
          title: Key Last4
        project_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Project Id
        client_email:
          anyOf:
            - type: string
            - type: 'null'
          title: Client Email
        aws_region:
          anyOf:
            - type: string
            - type: 'null'
          title: Aws Region
        access_key_id_last4:
          anyOf:
            - type: string
            - type: 'null'
          title: Access Key Id Last4
      type: object
      title: ProviderCredentialDisplayMetadata
      description: Non-secret metadata shown in the dashboard.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          additionalProperties: true
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````