# connectors.credentials.save

Store organization-scoped Stripe, Wise, or Notion credentials from the administrator dashboard. Values are encrypted server-side, never returned, and replace the prior credentials after verification. Requires idempotencyKey and the current revision when replacing.

`POST /api/v1/accounting/connectors.credentials.save`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Send `expectedRevision`

Not available over MCP: Provider secrets would pass through the agent.

## Fields

#### id: "stripe"

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | "stripe" | Yes | The record's ID. |
| `readKey` | string | Yes | at most 512 characters; Matches ^rk_(test\|live)_[A-Za-z0-9]+$. |
| `accountId` | string | Yes | The ID of a bank, card or payment account, from accounts.list. Matches ^acct_[A-Za-z0-9]+$. |
| `livemode` | boolean | Yes |  |
| `webhookSecret` | string |  | at most 512 characters; Matches ^whsec_[A-Za-z0-9]+$. |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

#### id: "wise"

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | "wise" | Yes | The record's ID. |
| `readToken` | string | Yes | 20–2048 characters. |
| `payoutToken` | string |  | 20–2048 characters. |
| `scaPrivateKey` | string |  | at most 8000 characters. |
| `environment` | enum | Yes | One of: `sandbox`, `production`. |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

#### id: "notion"

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | "notion" | Yes | The record's ID. |
| `token` | string | Yes | 20–1024 characters. |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/connectors.credentials.save \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "stripe",
  "readKey": "rk_test_a",
  "accountId": "acct_a",
  "livemode": true
}'
```

Reference page: https://app.getoatmilk.com/docs/api/connectors.credentials.save
