# Rotate org service account secret **POST /api/v1/organizations/{id}/service-accounts/{client_id}/rotate** Mints a new secret for an org-scoped customer service account. The previous secret keeps working for up to 7 days (or until its own expiration, if sooner) so callers can roll over without downtime. Body and secret_expires_after_hours are optional; omitted values default to 2160 (90 days). Requires ORG_ADMIN. ## Servers - https://agentengine.mongodb.com: https://agentengine.mongodb.com () ## Authentication methods - Bearer auth ## Parameters ### Path parameters - **id** (string) Organization ID - **client_id** (string) Service account client ID (ae_sa_id_*, legacy agp_sa_id_*) ### Body: application/json (object) Optional rotate request; defaults secret expiry to 90 days when omitted - **secret_expires_after_hours** (integer) Optional secret TTL in hours. Defaults to 2160 (90 days) when omitted, including an empty rotate body. ## Responses ### 406 Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence. #### Body: application/json (object) - **badRequestDetail** (object) Optional validation details defined by the standard error schema; API negotiation errors do not emit this field. - **detail** (string) Human-readable error details. - **error** (integer) HTTP status code. - **errorCode** (string) Machine-readable error code. - **parameters** (array[string]) Request parameter names associated with the error; omitted when none apply. - **reason** (string) HTTP status reason phrase. ### 200 OK #### Body: application/json (object) - **client_secret** (string) - **service_account** (object) ### 400 Bad Request #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 403 Forbidden #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 404 Not Found #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 429 Too Many Requests #### Headers - **Retry-After** (string) Seconds to wait before retrying #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 500 Internal Server Error #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 503 Service Unavailable #### Headers - **Retry-After** (string) Seconds to wait before retrying #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) [Powered by Bump.sh](https://bump.sh)