rotate_issue_space_token
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/rotate_issue_space_token, with a bearer credential and the action's payload as the JSON body.
Contract description
Re-mint a disclosed token of one space of an account's own, in place. Super-admin (platform operator) only. The issue service rotates the token and the vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered. An application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.
Access and action metadata
{
"name": "rotate_issue_space_token",
"resource": "account",
"tier": "reversible",
"grant": "super_admin",
"summary": "Re-mint a disclosed token of one space of an account's own in place, under the platform's provisioning credential. The vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered and no record of the space is read; an application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "rotate_issue_space_token",
"tier": "reversible",
"scenario": "API-L0-12",
"summary": "Re-mint a disclosed token of one space of an account's own, in place. Super-admin (platform operator) only. The issue service rotates the token and the vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered. An application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.",
"owners": [
"CRD-24"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["subject_account","space"] Additional properties: false |
| / |
The account id, from `list_accounts`. Type: string |
| / |
The identifier of a space of the account's own, a lower-case UUID, whose token the platform keeps under the account. An application's own space, and a space whose token entry is lost, are refused `not_found`. A space whose entry stands and which no longer stands at the issue service is refused `not_found` too: the empty space the rotation re-created is deleted, and nothing is written. Type: string Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","account","space","rotated"] Additional properties: false |
| / |
Required value: 1 |
| / |
Type: object Required fields: ["id","created_at","standing","synthetic"] Additional properties: false |
| / |
Type: string |
| / |
Type: string |
| / |
Allowed values: ["active","suspended"] |
| / |
Type: boolean |
| / |
The space whose token was rotated. Type: string |
| / |
The space's token is rotated at the issue service and its new value is written to the vault under the same custody entry. The token is never answered. Required value: true |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"subject_account",
"space"
],
"properties": {
"subject_account": {
"type": "string",
"description": "The account id, from `list_accounts`."
},
"space": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
"description": "The identifier of a space of the account's own, a lower-case UUID, whose token the platform keeps under the account. An application's own space, and a space whose token entry is lost, are refused `not_found`. A space whose entry stands and which no longer stands at the issue service is refused `not_found` too: the empty space the rotation re-created is deleted, and nothing is written."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"account",
"space",
"rotated"
],
"properties": {
"contract_version": {
"const": 1
},
"account": {
"type": "object",
"required": [
"id",
"created_at",
"standing",
"synthetic"
],
"properties": {
"id": {
"type": "string"
},
"created_at": {
"type": "string"
},
"standing": {
"enum": [
"active",
"suspended"
]
},
"synthetic": {
"type": "boolean"
}
},
"additionalProperties": false
},
"space": {
"type": "string",
"description": "The space whose token was rotated."
},
"rotated": {
"const": true,
"description": "The space's token is rotated at the issue service and its new value is written to the vault under the same custody entry. The token is never answered."
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md