> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Update workspace connector

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes a workspace connector. Send only the fields you want to change.

Send `client_secret` to rotate the secret. Connections already made keep working. Send `scopes` to change what new connections ask for. Connections already made keep the scopes they were granted.

To move a connector from your own OAuth app onto Base44's, send `credential_source` set to `base44`. The stored client ID and secret are dropped, and connections the apps' users made through your OAuth app are revoked after the response returns, so they have to connect again. A connector on Base44's OAuth app can't move back, and its client ID, secret, and `uses_oauth_gateway` can't change.

Before setting `uses_oauth_gateway` to `true`, register the gateway redirect URI from [Get OAuth redirect URIs](/api-reference/get-oauth-redirect-uris) in the provider's console. Setting it back to `false` always works.

This is limited to 30 requests per minute, shared by [Create workspace connector](/api-reference/create-workspace-connector), [Update workspace connector](/api-reference/update-workspace-connector), and [Delete workspace connector](/api-reference/delete-workspace-connector). A signed-in session has its own limit, and every personal access token for the workspace shares one. Some workspaces have a different limit.

<Note>Call this as an owner or admin of the workspace, with a personal access token for that workspace sent as a Bearer token, or from a signed-in session. A read-only token is refused. Workspace API keys aren't accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json put /api/workspace/{workspace_id}/connectors/{connector_id}
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/workspace/{workspace_id}/connectors/{connector_id}:
    put:
      summary: Update workspace connector
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Changes a workspace connector. Send only the fields you want to change.


        Send `client_secret` to rotate the secret. Connections already made keep
        working. Send `scopes` to change what new connections ask for.
        Connections already made keep the scopes they were granted.


        To move a connector from your own OAuth app onto Base44's, send
        `credential_source` set to `base44`. The stored client ID and secret are
        dropped, and connections the apps' users made through your OAuth app are
        revoked after the response returns, so they have to connect again. A
        connector on Base44's OAuth app can't move back, and its client ID,
        secret, and `uses_oauth_gateway` can't change.


        Before setting `uses_oauth_gateway` to `true`, register the gateway
        redirect URI from [Get OAuth redirect
        URIs](/api-reference/get-oauth-redirect-uris) in the provider's console.
        Setting it back to `false` always works.


        This is limited to 30 requests per minute, shared by [Create workspace
        connector](/api-reference/create-workspace-connector), [Update workspace
        connector](/api-reference/update-workspace-connector), and [Delete
        workspace connector](/api-reference/delete-workspace-connector). A
        signed-in session has its own limit, and every personal access token for
        the workspace shares one. Some workspaces have a different limit.


        <Note>Call this as an owner or admin of the workspace, with a personal
        access token for that workspace sent as a Bearer token, or from a
        signed-in session. A read-only token is refused. Workspace API keys
        aren't accepted.</Note>
      operationId: >-
        update_connector_api_workspace__workspace_id__connectors__connector_id__put
      parameters:
        - name: workspace_id
          in: path
          required: true
          schema:
            type: string
            description: >-
              ID of the workspace. With a personal access token, use the token's
              workspace. Get it from `organization_id` in [Get
              app](/api-reference/get-app).
            title: Workspace Id
          description: >-
            ID of the workspace. With a personal access token, use the token's
            workspace. Get it from `organization_id` in [Get
            app](/api-reference/get-app).
          example: 67e0b12c4d8a3f005b21c9e4
        - name: connector_id
          in: path
          required: true
          schema:
            type: string
            description: >-
              ID of the workspace connector to update, from `id` in [List
              workspace connectors](/api-reference/list-workspace-connectors).
            title: Connector Id
          description: >-
            ID of the workspace connector to update, from `id` in [List
            workspace connectors](/api-reference/list-workspace-connectors).
          example: 6820f3a4e7b91d003c45a1f9
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateOrganizationConnectorRequest'
      responses:
        '200':
          description: The updated workspace connector.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationConnectorResponse'
        '400':
          description: >-
            The change isn't allowed for a connector on Base44's OAuth app,
            `client_secret` is blank for a connector that needs one, a scope
            isn't available on Base44's OAuth app, a `connection_config` value
            is missing or invalid, or the connector can no longer be set up as a
            workspace connector.
        '401':
          description: Missing or invalid credentials.
        '402':
          description: >-
            `credential_source` is `base44` and the workspace's plan doesn't
            include Base44-managed connectors.
        '403':
          description: >-
            You aren't an owner or admin of the workspace, your token is for a
            different workspace or is read-only, your credential can't be used
            on this endpoint, or `uses_oauth_gateway` is `true` and the gateway
            callback isn't available to you.
        '404':
          description: >-
            Workspace connector not found in this workspace, or its connector
            isn't available to you.
        '409':
          description: >-
            Another connector in the workspace has this name, another request
            just moved the connector onto Base44's OAuth app, or the workspace
            requires an unlocked SSO session.
        '422':
          description: A field has the wrong type or format, or is empty.
        '429':
          description: Rate limit exceeded.
components:
  schemas:
    UpdateOrganizationConnectorRequest:
      properties:
        name:
          anyOf:
            - type: string
              minLength: 1
            - type: 'null'
          title: Name
          description: New name. Must be unique in the workspace, matching case exactly.
          example: Sales Google Calendar
        credential_source:
          anyOf:
            - type: string
              enum:
                - byo
                - base44
            - type: 'null'
          description: >-
            Send `base44` to move a connector from your own OAuth app onto
            Base44's. It can't move back. Moving drops the stored client ID and
            secret, and app users who connected through your OAuth app have to
            connect again.
          example: base44
        client_id:
          anyOf:
            - type: string
              maxLength: 512
              minLength: 1
            - type: 'null'
          title: Client Id
          description: >-
            New client ID of your OAuth app. Not accepted for a connector on
            Base44's OAuth app.
          example: 1234567890-abc123def456.apps.googleusercontent.com
        client_secret:
          anyOf:
            - type: string
              maxLength: 512
              minLength: 1
            - type: 'null'
          title: Client Secret
          description: >-
            New client secret of your OAuth app, to rotate it. Not accepted for
            a connector on Base44's OAuth app. It's stored encrypted and never
            returned.
          example: your-new-oauth-client-secret
        scopes:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Scopes
          description: New list of OAuth scopes, replacing the current one.
          example:
            - https://www.googleapis.com/auth/calendar
        connection_config:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Connection Config
          description: New connection values, replacing the current ones.
          example: {}
        uses_oauth_gateway:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Uses Oauth Gateway
          description: >-
            Whether new connections return to the single gateway redirect URI
            (`true`) or to the per-app ones (`false`). Register the matching
            URIs in the provider's console first, from [Get OAuth redirect
            URIs](/api-reference/get-oauth-redirect-uris). Not accepted for a
            connector on Base44's OAuth app, which always uses the gateway.
          example: true
      type: object
      title: UpdateOrganizationConnectorRequest
      description: The workspace connector fields to change. Leave out the ones to keep.
    OrganizationConnectorResponse:
      properties:
        id:
          type: string
          title: Id
          description: >-
            ID of the workspace connector. Pass it as `connector_id` to [Start
            connector connection](/api-reference/start-connector-connection).
          example: 6820f3a4e7b91d003c45a1f9
        organization_id:
          type: string
          title: Organization Id
          description: ID of the workspace.
          example: 67e0b12c4d8a3f005b21c9e4
        integration_type:
          type: string
          title: Integration Type
          description: Connector it's for.
          example: googlecalendar
        name:
          type: string
          title: Name
          description: Name of the workspace connector.
          example: Sales Google Calendar
        credential_source:
          type: string
          enum:
            - byo
            - base44
          description: >-
            Whose OAuth app it runs on: `byo` for the workspace's own, or
            `base44` for Base44's.
          default: byo
          example: byo
        client_id:
          type: string
          title: Client Id
          description: >-
            Client ID of the workspace's OAuth app. Empty for a connector on
            Base44's OAuth app.
          example: 1234567890-abc123def456.apps.googleusercontent.com
        scopes:
          items:
            type: string
          type: array
          title: Scopes
          description: OAuth scopes connections through it ask for.
          example:
            - https://www.googleapis.com/auth/calendar.readonly
        connection_config:
          additionalProperties:
            type: string
          type: object
          title: Connection Config
          description: >-
            Connection values saved on it, keyed by field name. Empty when the
            connector needs none.
          example: {}
        uses_oauth_gateway:
          type: boolean
          title: Uses Oauth Gateway
          description: >-
            Whether new connections return to the single gateway redirect URI
            (`true`) or to the per-app ones (`false`). [Get OAuth redirect
            URIs](/api-reference/get-oauth-redirect-uris) says which to
            register.
          default: false
          example: true
      type: object
      required:
        - id
        - organization_id
        - integration_type
        - name
        - client_id
        - scopes
      title: OrganizationConnectorResponse
      description: A workspace connector. The client secret is never returned.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.