> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-findings-decoys-followup.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Client Secret

> RotateClientSecret replaces a confidential App-owned client's secret and
 returns the new value once. The old secret stops working immediately; for
 an overlap window, create a second client, migrate, then delete the first.
 Public clients have no secret to rotate.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/apps/{app_id}/sso/applications/{id}/clients/rotate-secret
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/sso/applications/{id}/clients/rotate-secret:
    post:
      tags:
        - SSO
      summary: Rotate Client Secret
      description: |-
        RotateClientSecret replaces a confidential App-owned client's secret and
         returns the new value once. The old secret stops working immediately; for
         an overlap window, create a second client, migrate, then delete the first.
         Public clients have no secret to rotate.
      operationId: c1.api.sso.v1.SSOApplicationService.RotateClientSecret
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: Application that owns the client.
            type: string
        - in: path
          name: id
          required: true
          schema:
            description: SSO application that governs the client.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.sso.v1.SSOApplicationServiceRotateClientSecretRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.sso.v1.SSOApplicationServiceRotateClientSecretResponse
          description: >-
            SSOApplicationServiceRotateClientSecretResponse contains the
            replacement
             secret. The value cannot be retrieved again.
components:
  schemas:
    c1.api.sso.v1.SSOApplicationServiceRotateClientSecretRequestInput:
      description: |-
        SSOApplicationServiceRotateClientSecretRequest rotates one confidential
         App-owned client's secret.
      properties:
        clientId:
          description: Generated client ID whose secret will be rotated.
          type: string
      required:
        - clientId
      title: Sso Application Service Rotate Client Secret Request
      type: object
      x-speakeasy-name-override: SSOApplicationServiceRotateClientSecretRequest
    c1.api.sso.v1.SSOApplicationServiceRotateClientSecretResponse:
      description: |-
        SSOApplicationServiceRotateClientSecretResponse contains the replacement
         secret. The value cannot be retrieved again.
      properties:
        clientSecret:
          description: New client secret, shown exactly once.
          type: string
      title: Sso Application Service Rotate Client Secret Response
      type: object
      x-speakeasy-name-override: SSOApplicationServiceRotateClientSecretResponse
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````