Rotate an SMPP credential's password and return the new plaintext once
Issue a new SMPP bind password for an existing BYO-SMPP credential when the plaintext is lost (the 60-second reveal window expired), when the secret may be compromised, or on a scheduled rotation cycle. The credential’s systemId and every config field stay unchanged; only the password is replaced. The new plaintext is returned EXACTLY ONCE in this response — store it now. Owner / admin only, rate-limited to 10 per hour per tenant. A 409 fires when the credential is revoked (create a new one instead), and 404 when no credential holds the id.
Authorizations
Dashboard JWT token from Clerk
Headers
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Path Parameters
Response
The rotated credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable. Fields match the create response (id, systemId, description, tpsLimit, allowedCidrs, dlrMode, dlrWebhookUrl, status, lastRotatedAt, bindCount, smppHost, smppPort, passwordRevealableUntil).
The rotated credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable. Fields match the create response (id, systemId, description, tpsLimit, allowedCidrs, dlrMode, dlrWebhookUrl, status, lastRotatedAt, bindCount, smppHost, smppPort, passwordRevealableUntil).