> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anyreach.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Patch Credential Value

> Add, overwrite or remove individual keys of a static credential's value.

The whole-value PUT cannot express this: the value is one encrypted blob the
client is never allowed to read, so replacing it wholesale would silently
drop every key the caller did not happen to retype. The merge belongs on the
server, which is the only side that can decrypt.



## OpenAPI

````yaml /openapi.json patch /workflow/credentials/{credential_id}/value
openapi: 3.1.0
info:
  title: Anyreach API
  version: 1.0.0
  description: >-
    REST API for the Anyreach platform.


    Every endpoint is scoped to one organization. Authenticate with a bearer
    token and, if your token can reach more than one organization, name the one
    you mean with the `X-Anyreach-Org` header. See
    [Authentication](https://docs.anyreach.ai/api-reference/authentication).


    This reference is generated from the running service, so the request and
    response shapes here are the ones the API actually enforces.
servers:
  - url: https://api.anyreach.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Agents
    description: >-
      Create and configure the agent that handles a conversation, and manage its
      versions. An agent's behaviour lives in a version; publishing a version is
      what puts it on the air.
  - name: Conversations
    description: >-
      Create, list, retrieve, and message conversations between your users and
      Anyreach agents.
  - name: Conversation attachments
    description: >-
      Upload files into a conversation and read them back. Uploads are two-step:
      presign, PUT to the returned URL, then mark the attachment complete.
  - name: Conversation events
    description: >-
      The ordered event stream behind a conversation — turns, tool calls,
      transfers, and status changes.
  - name: Knowledge bases
    description: >-
      A knowledge base (a `dataset` in the API) is a collection of embedded
      content an agent can retrieve from.
  - name: Knowledge base sources
    description: Attach and detach sources to a knowledge base.
  - name: Sources
    description: >-
      A source is a file or URL whose content is ingested, chunked, and
      embedded.
  - name: Phone numbers
    description: >-
      Buy, list, and release phone numbers, and point each one at the agent that
      should answer it.
  - name: Trunks
    description: >-
      SIP trunks for bringing your own carrier. A trunk carries calls between
      your carrier and Anyreach.
  - name: Inbound routing
    description: >-
      Rules that decide which agent answers an inbound call, evaluated before
      the call connects.
  - name: Agent assist
    description: >-
      Look up the live-assist context for a number so a human agent can see what
      the AI agent knows.
  - name: Human handoff
    description: >-
      Connections to the help desk a conversation escalates into, and the test
      endpoint that proves one works.
  - name: Email domains
    description: >-
      Register a sending domain and verify its DNS before an agent can send from
      it.
  - name: Email addresses
    description: >-
      The addresses on a verified domain, and the agent that handles mail
      arriving at each one.
  - name: Unsubscribes
    description: >-
      The suppression list. An address on this list is never emailed again until
      it is removed.
  - name: Web widgets
    description: >-
      The embeddable chat and voice widget: its appearance, its allowed domains,
      and the agent behind it.
  - name: Campaigns
    description: >-
      An outbound campaign dials a contact list with a given agent on a given
      schedule. Start, pause, and close control its lifecycle.
  - name: Campaign contacts
    description: >-
      The people a campaign dials. Contacts can be added while the campaign is
      running.
  - name: Campaign configurations
    description: >-
      Reusable dialing settings — calling windows, retry policy, timezone
      handling — that campaigns reference.
  - name: Campaign stats
    description: >-
      Per-campaign outcome counters, and the organization-wide cap on how many
      calls run at once.
  - name: Custom data
    description: >-
      Your own tables, queryable by an agent mid-conversation. Define a table,
      load rows, and expose read-only stored queries as agent tools.
  - name: Metrics
    description: >-
      The definitions an LLM judge scores a conversation against. Lint and
      preview a metric before you run it at scale.
  - name: Evaluations
    description: A scorecard binding a set of metrics to a population of conversations.
  - name: Evaluation runs
    description: >-
      One execution of an evaluation over a conversation set, and the results it
      produced.
  - name: Workflows
    description: >-
      Automations built from steps. A workflow is edited as a version and goes
      live when a version is published and set live.
  - name: Workflow triggers
    description: >-
      What starts a workflow — a schedule, a webhook, or a point in an agent
      conversation. Triggers are versioned alongside the workflow.
  - name: Workflow executions
    description: >-
      Run a workflow and read back what happened. Executions are synchronous by
      default; use the async endpoint for long-running work.
  - name: Workflow credentials
    description: >-
      Secrets a workflow step authenticates with. Values are write-only — they
      can be set and rotated, never read back.
paths:
  /workflow/credentials/{credential_id}/value:
    patch:
      tags:
        - Workflow credentials
      summary: Patch Credential Value
      description: >-
        Add, overwrite or remove individual keys of a static credential's value.


        The whole-value PUT cannot express this: the value is one encrypted blob
        the

        client is never allowed to read, so replacing it wholesale would
        silently

        drop every key the caller did not happen to retype. The merge belongs on
        the

        server, which is the only side that can decrypt.
      operationId: patchCredentialValue
      parameters:
        - name: credential_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Credential Id
        - name: x-anyreach-org
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            description: Organization ID for user PATs (pat_ prefix tokens)
            title: X-Anyreach-Org
          description: Organization ID for user PATs (pat_ prefix tokens)
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CredentialValuePatchSchema'
      responses:
        '204':
          description: Successful Response
        '404':
          description: Not found
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - HTTPBearer: []
components:
  schemas:
    CredentialValuePatchSchema:
      properties:
        set:
          additionalProperties:
            type: string
          type: object
          title: Set
          default: {}
        delete:
          items:
            type: string
          type: array
          title: Delete
          default: []
        expires_at:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Expires At
      type: object
      title: CredentialValuePatchSchema
      description: >-
        A partial edit of a static credential's value.


        Per-key rather than whole-value because the value is a single encrypted
        blob

        the client cannot read: to overwrite one key without wiping the rest,
        the

        merge has to happen on the server, which is the only side that can
        decrypt.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Personal access token or organization API key. See Authentication.

````