Update partner credential scopes
Replaces the credential scopes. Scopes must be a non-empty subset of the public read allowlist. Casa updates the issuer application first, then the grant row. Session auth only.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for first-party machines and MCP clients), a partner credential access token (third-party agents; REST-only), a session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. Partner credentials reject X-Property-Id. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Headers
Active organization (property group). Optional cross-check for session (JWT) auth: when sent it must equal the token's verified org_id claim, else 403. The org is taken from the claim, not this header. Ignored for API keys, partner credentials, and static tokens.
Path Parameters
Resource id (UUID).
Body
Response
Updated credential.
An org-scoped partner credential. Casa never returns or stores the plaintext client secret after create or rotate.