Connectors and webhooks

connectors.credentials.save

Store organization-scoped Stripe, Wise, or Notion credentials from the administrator dashboard. Values are encrypted server-side, never returned, and replace the prior credentials after verification. Requires idempotencyKey and the current revision when replacing.

POST/api/v1/accounting/connectors.credentials.save

Permissions

accounting:readaccounting:writeaccounting:admin

Who can call it

admin

Retries

Idempotency key required, with expectedRevision

MCP

Not offered over MCP: Provider secrets would pass through the agent.

Fields

Shape 1: id: "stripe"

  • id"stripe"Required

    The record's ID.

  • readKeystringRequired

    at most 512 characters · Matches ^rk_(test|live)_[A-Za-z0-9]+$

  • accountIdstringRequired

    The ID of a bank, card or payment account, from accounts.list.

    Matches ^acct_[A-Za-z0-9]+$

  • livemodebooleanRequired
  • webhookSecretstring

    at most 512 characters · Matches ^whsec_[A-Za-z0-9]+$

  • expectedRevisioninteger

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    0 to 9007199254740991

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Shape 2: id: "wise"

  • id"wise"Required

    The record's ID.

  • readTokenstringRequired

    20–2048 characters

  • payoutTokenstring

    20–2048 characters

  • scaPrivateKeystring

    at most 8000 characters

  • environmentenumRequired
    sandboxproduction
  • expectedRevisioninteger

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    0 to 9007199254740991

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Shape 3: id: "notion"

  • id"notion"Required

    The record's ID.

  • tokenstringRequired

    20–1024 characters

  • expectedRevisioninteger

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    0 to 9007199254740991

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/connectors.credentials.save \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "stripe",
  "readKey": "rk_test_a",
  "accountId": "acct_a",
  "livemode": true
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/connectors.credentials.save
curl https://app.getoatmilk.com/api/v1/accounting/connectors.credentials.save \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "stripe",
  "readKey": "rk_test_a",
  "accountId": "acct_a",
  "livemode": true
}'

More in Connectors and webhooks.