# Update an integration

> Change an integration: its name, its config (replaced whole when given) or its secret (a new key replaces the old one, write-only).

<div class="g1t-endpoint"><span class="g1t-method" data-method="patch">PATCH</span><code>/workspaces/{workspace}/integrations/{id}</code></div>

Use it to rotate a model provider's key or to choose its config.gateway_models, the AI Gateway models it takes. Fields left out are kept. Secrets are never returned. Owners only.

The secret is write-only: it is kept encrypted and only its last four characters come back, as `secret_hint`. With `gateway_models` set to `ollama/*`, an AI Gateway request for `ollama/qwen3-coder:30b` reaches this endpoint as `qwen3-coder:30b`, on the workspace's own account. See [the AI Gateway guide](/guides/ai-gateway/#your-own-providers).

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`workspace`](/reference/mcp/#workspace) with `action` `update_integration`, and the same inputs
- **Scope:** An access token needs [`workspace:admin`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `workspace` | string | Yes | The workspace's slug, e.g. "flagon-io". |
| `id` | string | Yes | The integration's id. |

## Body parameters

Send a JSON object. Names are `snake_case`, as in responses; the `camelCase` spelling is accepted too.

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | No | A new name. |
| `config` | object | No | Its settings, replaced whole: the same fields as connect_integration's config. For a model provider, gateway_models chooses the AI Gateway models it takes. |
| `secret` | string | No | A new API key or token, replacing the old one. Write-only: kept encrypted, never returned. |
| `signing_secret` | string | No | For sentry: a new client secret. |

## Example request

```sh
curl -X PATCH https://api.g1t.sh/workspaces/flagon-io/integrations/con_01kpx5c2d8e4f6g0h2j4k6m8n0 \
  -H "Authorization: Bearer $G1T_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "config": {
      "base_url": "https://gpu.flagon.dev/v1",
      "gateway_models": [
        "ollama/*"
      ]
    },
    "secret": "sk-office-gpu-key"
  }'
```

## Example response

A successful request answers `200` with:

```json
{
  "id": "con_01kpx5c2d8e4f6g0h2j4k6m8n0",
  "workspace": "flagon-io",
  "provider": "openai_endpoint",
  "kind": "models",
  "name": "Office GPU",
  "config": {
    "write_back": true,
    "base_url": "https://gpu.flagon.dev/v1",
    "gateway_models": [
      "ollama/*"
    ]
  },
  "secret_hint": "…-key",
  "webhook_url": null,
  "created_by": "syntaqx",
  "created_at": "2026-10-07T12:10:44.512Z",
  "last_used_at": "2026-10-07T14:00:02.000Z",
  "last_error": null,
  "models": [
    "llama3.3:70b",
    "qwen3-coder:30b"
  ]
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 409 | `conflict` | The request conflicts with the current state. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
