rotate_issue_space_token

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/rotate_issue_space_token, with a bearer credential and the action's payload as the JSON body.

Contract description

Re-mint a disclosed token of one space of an account's own, in place. Super-admin (platform operator) only. The issue service rotates the token and the vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered. An application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.

Access and action metadata

{
  "name": "rotate_issue_space_token",
  "resource": "account",
  "tier": "reversible",
  "grant": "super_admin",
  "summary": "Re-mint a disclosed token of one space of an account's own in place, under the platform's provisioning credential. The vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered and no record of the space is read; an application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": true,
    "openWorldHint": false
  }
}

MCP catalog entry

{
  "name": "rotate_issue_space_token",
  "tier": "reversible",
  "scenario": "API-L0-12",
  "summary": "Re-mint a disclosed token of one space of an account's own, in place. Super-admin (platform operator) only. The issue service rotates the token and the vault takes the new value under the same entry, so the account's bound applications keep working and the earlier token is refused. The token is never answered. An application's own space, or one whose token entry is lost, is refused `not_found`. So is a space that no longer stands at the issue service. A failure once the rotate call is sent names the space and may leave the token rotated, so run the act again.",
  "owners": [
    "CRD-24"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["subject_account","space"]
Additional properties: false
/properties/subject_account The account id, from `list_accounts`.

Type: string
/properties/space The identifier of a space of the account's own, a lower-case UUID, whose token the platform keeps under the account. An application's own space, and a space whose token entry is lost, are refused `not_found`. A space whose entry stands and which no longer stands at the issue service is refused `not_found` too: the empty space the rotation re-created is deleted, and nothing is written.

Type: string
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","account","space","rotated"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/account Type: object
Required fields: ["id","created_at","standing","synthetic"]
Additional properties: false
/properties/account/properties/id Type: string
/properties/account/properties/created_at Type: string
/properties/account/properties/standing Allowed values: ["active","suspended"]
/properties/account/properties/synthetic Type: boolean
/properties/space The space whose token was rotated.

Type: string
/properties/rotated The space's token is rotated at the issue service and its new value is written to the vault under the same custody entry. The token is never answered.

Required value: true
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "subject_account",
      "space"
    ],
    "properties": {
      "subject_account": {
        "type": "string",
        "description": "The account id, from `list_accounts`."
      },
      "space": {
        "type": "string",
        "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
        "description": "The identifier of a space of the account's own, a lower-case UUID, whose token the platform keeps under the account. An application's own space, and a space whose token entry is lost, are refused `not_found`. A space whose entry stands and which no longer stands at the issue service is refused `not_found` too: the empty space the rotation re-created is deleted, and nothing is written."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "account",
      "space",
      "rotated"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "account": {
        "type": "object",
        "required": [
          "id",
          "created_at",
          "standing",
          "synthetic"
        ],
        "properties": {
          "id": {
            "type": "string"
          },
          "created_at": {
            "type": "string"
          },
          "standing": {
            "enum": [
              "active",
              "suspended"
            ]
          },
          "synthetic": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "space": {
        "type": "string",
        "description": "The space whose token was rotated."
      },
      "rotated": {
        "const": true,
        "description": "The space's token is rotated at the issue service and its new value is written to the vault under the same custody entry. The token is never answered."
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
}

Shared contracts