Submit and validate provider credentials
Live-validates the supplied provider credentials and stores them on the connection. The connection flips to connected only when the provider call succeeds; a failed validation returns a sanitized 400 and never persists (or overwrites) secrets. Requires scope write:integrations.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for machines and MCP clients), a WorkOS AuthKit session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Path Parameters
Resource id (UUID).
Body
Provider-specific credential fields (e.g. access_token, client_token).
Response
Validated and stored.
"connected"