Skip to content
Helicarrier Developers

Rotate database credentials

Change a managed database’s password and invalidate the previous credential.

POST /api/services/{id}/db/password HTTPS
Request & response examples
Request example Server-side
curl --fail-with-body --request POST \
'https://app.helicarrier.xyz/api/services/YOUR_ID/db/password' \
-H "Authorization: Bearer $HELI_API_KEY" \
-H 'Content-Type: application/json' \
--data '{
"password": "REPLACE_WITH_A_STRONG_SECRET"
}'
Response example 200
{
"status": "password changed"
}

Illustrative values · selected fields

Authorization

An account key with access to the resource. Project and service keys do not authorize this operation.

Authorization: Bearer <key> Key setup ↗

Path parameters

id string required

Database or bucket service id.

Request body

password string required

New password (databases) or secret key (buckets, min 8 characters).

accessKey string optional

Buckets only: a new S3 access key. Omit to keep the current one.

Response 200

Returns confirmation after changing the database password. Update clients that hold the old credential; do not publish the replacement password.

Examples show selected response fields with illustrative values. Your response can contain additional fields.

status string

Current state of the resource or operation.

Errors

400

Invalid parameters. Check the required fields, types, and resource configuration.

401

The API key is missing, invalid, or revoked.

403

The caller or key scope does not permit this operation.

500

The operation could not be completed. Check resource state before retrying a write.

Error handling and safe retries
ALSO AVAILABLE VIA MCP

rotate_db_credentials

Required MCP arguments: id, password. Send path, query, and body fields together as tool arguments.

Connect your agent ↗