connectors.credentials.save
Store organization-scoped Stripe, Wise, or Notion credentials from the administrator dashboard. Values are encrypted server-side, never returned, and replace the prior credentials after verification. Requires idempotencyKey and the current revision when replacing.
/api/v1/accounting/connectors.credentials.savePermissions
Who can call it
Retries
MCP
Fields
Shape 1: id: "stripe"
id"stripe"RequiredThe record's ID.
readKeystringRequiredat most 512 characters · Matches ^rk_(test|live)_[A-Za-z0-9]+$
accountIdstringRequiredThe ID of a bank, card or payment account, from accounts.list.
Matches ^acct_[A-Za-z0-9]+$
livemodebooleanRequiredwebhookSecretstringat most 512 characters · Matches ^whsec_[A-Za-z0-9]+$
expectedRevisionintegerThe record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.
0 to 9007199254740991
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
Shape 2: id: "wise"
id"wise"RequiredThe record's ID.
readTokenstringRequired20–2048 characters
payoutTokenstring20–2048 characters
scaPrivateKeystringat most 8000 characters
environmentenumRequiredsandboxproductionexpectedRevisionintegerThe record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.
0 to 9007199254740991
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
Shape 3: id: "notion"
id"notion"RequiredThe record's ID.
tokenstringRequired20–1024 characters
expectedRevisionintegerThe record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.
0 to 9007199254740991
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
Example
curl https://app.getoatmilk.com/api/v1/accounting/connectors.credentials.save \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"id": "stripe",
"readKey": "rk_test_a",
"accountId": "acct_a",
"livemode": true
}'{
"data": { … }
}Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/connectors.credentials.save \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"id": "stripe",
"readKey": "rk_test_a",
"accountId": "acct_a",
"livemode": true
}'More in Connectors and webhooks.