> ## Documentation Index
> Fetch the complete documentation index at: https://hub.hcompany.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate the token

> Replace a vault's stored service account token.

export const Notice = ({kind = "note", title, children}) => {
  const kinds = {
    warning: {
      label: "User notice",
      icon: <>
          <path d="m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3" />
          <path d="M12 9v4" />
          <path d="M12 17h.01" />
        </>
    },
    gotcha: {
      label: "Gotcha",
      icon: <>
          <circle cx="12" cy="12" r="10" />
          <path d="M12 16v-4" />
          <path d="M12 8h.01" />
        </>
    },
    note: {
      label: "Note",
      icon: <>
          <circle cx="12" cy="12" r="10" />
          <path d="M12 16v-4" />
          <path d="M12 8h.01" />
        </>
    }
  };
  const k = kinds[kind];
  return <div className="notice my-6 rounded-xl border border-zinc-200 bg-white p-5 dark:border-zinc-800 dark:bg-zinc-950">
      <div className={`${kind === "warning" ? "not-prose flex items-center gap-1.5 text-xs font-semibold uppercase tracking-wide text-red-400/80 dark:text-red-400/70" : kind === "gotcha" ? "not-prose flex items-center gap-1.5 text-xs font-semibold uppercase tracking-wide text-amber-500/80 dark:text-amber-400/70" : "not-prose flex items-center gap-1.5 text-xs font-semibold uppercase tracking-wide text-zinc-400 dark:text-zinc-500"}`}>
        <svg className="h-3.5 w-3.5" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round">
          {k.icon}
        </svg>
        {k.label}
      </div>
      {title && <div className="not-prose mt-2 text-base font-semibold text-zinc-900 dark:text-zinc-100">{title}</div>}
      <div className="notice-body mt-3 text-sm leading-6 text-zinc-700 dark:text-zinc-300">{children}</div>
    </div>;
};

Replaces the service account token stored for a vault config. The new token is health-checked against the provider before it is written, so a token that cannot reach `op_vault_id` is rejected and the old one stays in place.

Returns `204 No Content` on success.

<Notice kind="warning" title="Plaintext token in the request body">
  The service account token travels in clear text inside the body. Send it only over HTTPS and never log the request. Rotation is not idempotent: a retry after a 5xx may apply twice.
</Notice>

***

## Path parameters

<ParamField path="vault_id" type="string" required>
  The vault config's `id` (UUID).
</ParamField>

***

## Request body

<ParamField body="token" type="string" required>
  The new 1Password service account token. Write-only and never returned.
</ParamField>

***

## Examples

<CodeGroup>
  ```bash cURL theme={"system"}
  curl -X PUT https://agp.eu.hcompany.ai/api/v2/vaults/f47ac10b-58cc-4372-a567-0e02b2c3d479/token \
    -H "Authorization: Bearer $HAI_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{"token": "ops_newtoken..."}'
  ```

  ```python Python theme={"system"}
  from hai_agents import Client

  client = Client()

  client.vaults.rotate_vault_token(
      vault_id="f47ac10b-58cc-4372-a567-0e02b2c3d479",
      token="ops_newtoken...",
  )
  ```

  ```typescript TypeScript theme={"system"}
  import { HaiAgentsClient } from "hai-agents";

  const client = new HaiAgentsClient();

  await client.vaults.rotateVaultToken({
    vaultId: "f47ac10b-58cc-4372-a567-0e02b2c3d479",
    token: "ops_newtoken...",
  });
  ```
</CodeGroup>

***

## Errors

| Status | Cause                                                               |
| ------ | ------------------------------------------------------------------- |
| `404`  | Vault not found or you don't have access.                           |
| `422`  | The provider rejected the new token. The stored token is unchanged. |
