---
title: "rotateAgentCredential"
description: "Rotate an agent credential's secrets"
canonical: "https://pgbeam.com/docs/ts-sdk/agents/rotateAgentCredential"
last-updated: "2026-09-14T19:37:21.000Z"
---

# rotateAgentCredential

> Rotate an agent credential's secrets

URL: https://pgbeam.com/docs/ts-sdk/agents/rotateAgentCredential

Generates a new Postgres password and MCP token for the credential in place, keeping the same id, username, name, and policy. Live connections using the old password are dropped within seconds. The new secrets are returned once and cannot be retrieved again.

## Usage

## Parameters

Parameter

Type

Required

Description

pathParams.project\_id

`string`

Yes

Unique project identifier (prefixed, e.g. prj\_xxx).

pathParams.agent\_id

`string`

Yes

Unique agent credential identifier (prefixed, e.g. agt\_xxx).

## Response

`Promise<AgentCredentialSecrets>`: secrets rotated. new secrets shown once.

## Example

## Errors

Status

Description

400

The request was rejected. `code` is `INVALID_INPUT`, and `errors` names the offending fields when the failure was a validation one.

401

Missing or invalid authentication. `code` is `UNAUTHORIZED`.

403

The caller is authenticated but not allowed to perform this operation. `code` is `FORBIDDEN` when the caller's role is insufficient, and `PLAN_LIMIT_REACHED` when the organization's plan is what stands in the way. The two are answered differently, so branch on the code rather than the status.

404

The resource does not exist, or the caller is not entitled to know that it does. `code` is `NOT_FOUND`.

409

The credential is revoked and cannot be rotated.

500

The request failed for a reason on our side. `code` is `INTERNAL_ERROR`. Quote `request_id` when reporting it.