> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a connection's name and credentials.



## OpenAPI

````yaml /openapi-public.json put /connections/{id}
openapi: 3.1.1
info:
  title: Klef API
  description: Klef's multi-tenant HRIS sync platform API.
  version: v1
servers:
  - url: https://{workspace}.klef.ai/api
    variables:
      workspace:
        default: acme
        description: Your workspace's subdomain.
security: []
tags:
  - name: Users
  - name: Connections
  - name: Adoption
  - name: Policy resources
  - name: Audit
  - name: Catalog
  - name: Sync
  - name: Search
  - name: SyncPlans
  - name: Agent
  - name: Auth
  - name: Workspaces
  - name: Billing
  - name: Invitations
  - name: FirstSignIns
  - name: Connection accounts
  - name: Policies
  - name: Secrets
  - name: Lookup tables
  - name: Scripts
  - name: Segments
  - name: ApiKeys
  - name: Members
  - name: Workers
  - name: Inbox
  - name: Notifications
paths:
  /connections/{id}:
    put:
      tags:
        - Connections
      summary: Replace a connection's name and credentials.
      operationId: UpdateConnection
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: If-Match
          in: header
          description: >-
            Strong ETag (e.g. "3") of the resource's current version, from the
            most recent GET or write. Required for the write to proceed; a
            missing header returns 428, a malformed value returns 400.
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateConnectionRequest'
        required: true
      responses:
        '204':
          description: No Content
          headers:
            ETag:
              description: >-
                Strong ETag for the resource's current version. Send back as
                `If-Match` on the next write to assert the version observed.
              required: true
              schema:
                type: string
        '400':
          description: Validation or business-rule error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '412':
          description: >-
            If-Match did not match the current resource version; reload and
            retry.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '428':
          description: If-Match header is required.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                required:
                  - result
                  - errors
                type: object
                properties:
                  result: {}
                  errors:
                    type: array
                    items:
                      required:
                        - errorCode
                        - errorMessage
                      type: object
                      properties:
                        errorCode:
                          enum:
                            - validation_error
                            - unauthorized
                            - forbidden
                            - not_found
                            - internal_error
                            - error
                            - precondition_required
                            - precondition_failed
                            - invalid_if_match
                            - worker_not_found
                            - worker_version_not_found
                            - connection_not_found
                            - policy_not_found
                            - policy_revision_not_found
                            - lookup_table_not_found
                            - script_not_found
                            - segment_not_found
                            - workspace_secret_not_found
                            - member_not_found
                            - invitation_not_found
                            - user_not_found
                            - workspace_not_found
                            - api_key_not_found
                            - inbox_item_not_found
                            - sync_plan_not_found
                            - connection_account_not_found
                            - managed_account_not_found
                            - adoption_run_not_found
                            - sync_plan_not_ready
                            - sync_plan_stale
                            - sync_plan_already_applying
                            - subdomain_taken
                            - invalid_subdomain
                            - invalid_invite
                            - last_owner_protected
                            - owner_protected
                            - already_member
                            - already_invited
                            - role_not_assignable
                            - invalid_email
                            - email_required
                            - email_mismatch
                            - invitation_gone
                            - invalid_connector_credentials
                            - wrong_connector_type
                            - connection_not_syncable
                            - connector_o_auth_not_configured
                            - connector_authorization_failed
                            - salesforce_manage_users_required
                            - box_admin_required
                            - linear_admin_required
                            - dropbox_admin_required
                            - invalid_match_rule
                            - adoption_run_composed
                            - adoption_run_empty
                            - adoption_selection_refused
                            - invalid_policy
                            - policy_does_not_compile
                            - policy_secret_missing
                            - policy_lookup_table_missing
                            - policy_script_missing
                            - policy_segment_missing
                            - policy_edit_target_missing
                            - policy_secret_disclosure_forbidden
                            - notification_send_failed
                            - invalid_workspace_secret
                            - workspace_secret_referenced
                            - workspace_secret_name_conflict
                            - invalid_lookup_table
                            - lookup_table_referenced
                            - lookup_table_name_conflict
                            - invalid_script
                            - script_name_conflict
                            - script_referenced
                            - invalid_segment
                            - segment_name_conflict
                            - segment_referenced
                            - segment_worker_missing
                            - api_key_scope_not_granted
                            - api_key_limit_reached
                            - subscription_required
                            - already_subscribed
                            - no_billing_customer
                            - workspace_pending_deletion
                            - workspace_deletion_confirmation_mismatch
                            - workspace_deletion_already_scheduled
                            - workspace_deletion_not_scheduled
                            - workspace_export_expired
                            - workspace_export_not_found
                            - agent_conversation_not_found
                            - agent_proposal_not_found
                            - agent_proposal_outdated
                            - agent_proposal_expired
                            - agent_proposal_already_applied
                            - agent_proposal_rejected
                            - notification_kind_unsupported
                            - first_sign_in_not_found
                            - first_sign_in_gone
                            - first_sign_in_not_a_recipient
                            - first_sign_in_recipient_unknown
                            - first_sign_in_locked
                            - first_sign_in_code_refused
                            - first_sign_in_proof_invalid
                            - password_reset_unsupported
                            - invalid_password_rules
                            - avatar_not_owned
                            - unsupported_image_type
                            - image_too_large
                          description: >-
                            The central catalog of every error returned by the
                            API.
                        errorMessage:
                          type: string
                        target:
                          type:
                            - 'null'
                            - string
                      description: "One error in an API response: a specific ApiErrorCode, a human-readable message,\r\n    and an optional string? ApiError.Target (the field a validation error applies to)."
                description: "The envelope for a single-resource response: T? ApiResponse&lt;T&gt;.Result on success, otherwise `null`\r\n    with one or more IReadOnlyList&lt;ApiError&gt; ApiResponse&lt;T&gt;.Errors."
      security:
        - cookieAuth: []
        - apiKeyAuth: []
components:
  schemas:
    UpdateConnectionRequest:
      required:
        - name
        - credentials
      type: object
      properties:
        name:
          type:
            - 'null'
            - string
        credentials:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/ConnectionCredentialsRequest'
        protected:
          type:
            - 'null'
            - boolean
    ConnectionCredentialsRequest:
      required:
        - connectorType
      type: object
      anyOf:
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAdpConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestOracleFusionConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestEntraConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestGoogleWorkspaceConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAwsConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAwsIdentityCenterConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAzureConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestGithubEnterpriseConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestOpenaiConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAnthropicConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestOnePasswordConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestKeeperConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestBitwardenConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestAtlassianConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestNotionConnectionCredentialsRequest
        - $ref: >-
            #/components/schemas/ConnectionCredentialsRequestBambooHrConnectionCredentialsRequest
      discriminator:
        propertyName: connectorType
        mapping:
          adp_workforce_now:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAdpConnectionCredentialsRequest
          oracle_fusion:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestOracleFusionConnectionCredentialsRequest
          microsoft_entra:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestEntraConnectionCredentialsRequest
          google_workspace:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestGoogleWorkspaceConnectionCredentialsRequest
          aws:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAwsConnectionCredentialsRequest
          aws_identity_center:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAwsIdentityCenterConnectionCredentialsRequest
          azure:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAzureConnectionCredentialsRequest
          github_enterprise:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestGithubEnterpriseConnectionCredentialsRequest
          openai:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestOpenaiConnectionCredentialsRequest
          anthropic:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAnthropicConnectionCredentialsRequest
          one_password:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestOnePasswordConnectionCredentialsRequest
          keeper:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestKeeperConnectionCredentialsRequest
          bitwarden:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestBitwardenConnectionCredentialsRequest
          atlassian:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestAtlassianConnectionCredentialsRequest
          notion:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestNotionConnectionCredentialsRequest
          bamboo_hr:
            $ref: >-
              #/components/schemas/ConnectionCredentialsRequestBambooHrConnectionCredentialsRequest
    ConnectionCredentialsRequestAdpConnectionCredentialsRequest:
      required:
        - clientId
        - baseUrl
        - clientSecret
        - sslClientCertPem
        - sslClientKeyPem
      properties:
        connectorType:
          enum:
            - adp_workforce_now
          type: string
        clientId:
          type: string
        baseUrl:
          type:
            - 'null'
            - string
        clientSecret:
          type: string
        sslClientCertPem:
          type:
            - 'null'
            - string
        sslClientKeyPem:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestOracleFusionConnectionCredentialsRequest:
      required:
        - baseUrl
        - username
        - password
      properties:
        connectorType:
          enum:
            - oracle_fusion
          type: string
        baseUrl:
          type: string
        username:
          type: string
        password:
          type: string
    ConnectionCredentialsRequestEntraConnectionCredentialsRequest:
      required:
        - tenantId
        - clientId
        - clientSecret
      properties:
        connectorType:
          enum:
            - microsoft_entra
          type: string
        tenantId:
          type: string
        clientId:
          type: string
        clientSecret:
          type: string
        exchangeOrganization:
          type:
            - 'null'
            - string
        exchangeCertificatePfx:
          type:
            - 'null'
            - string
        exchangeCertificatePassword:
          type:
            - 'null'
            - string
        firstSignInKind:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/FirstSignInKind'
        passLifetimeMinutes:
          maximum: 43200
          minimum: 10
          type:
            - 'null'
            - integer
          format: int32
        passUsableOnce:
          type:
            - 'null'
            - boolean
    ConnectionCredentialsRequestGoogleWorkspaceConnectionCredentialsRequest:
      required:
        - serviceAccountKeyJson
        - adminEmail
        - customerId
      properties:
        connectorType:
          enum:
            - google_workspace
          type: string
        serviceAccountKeyJson:
          type: string
        adminEmail:
          type: string
        customerId:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestAwsConnectionCredentialsRequest:
      required:
        - accessKeyId
        - secretAccessKey
      properties:
        connectorType:
          enum:
            - aws
          type: string
        accessKeyId:
          type: string
        secretAccessKey:
          type: string
        region:
          type:
            - 'null'
            - string
        roleArn:
          type:
            - 'null'
            - string
        externalId:
          type:
            - 'null'
            - string
        organizationRoleName:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestAwsIdentityCenterConnectionCredentialsRequest:
      required:
        - accessKeyId
        - secretAccessKey
        - region
      properties:
        connectorType:
          enum:
            - aws_identity_center
          type: string
        accessKeyId:
          type: string
        secretAccessKey:
          type: string
        region:
          type: string
        roleArn:
          type:
            - 'null'
            - string
        externalId:
          type:
            - 'null'
            - string
        instanceArn:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestAzureConnectionCredentialsRequest:
      required:
        - tenantId
        - clientId
        - clientSecret
        - scope
      properties:
        connectorType:
          enum:
            - azure
          type: string
        tenantId:
          type: string
        clientId:
          type: string
        clientSecret:
          type: string
        scope:
          type: string
        assignmentMode:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestGithubEnterpriseConnectionCredentialsRequest:
      required:
        - enterprise
        - baseUrl
        - token
      properties:
        connectorType:
          enum:
            - github_enterprise
          type: string
        enterprise:
          type: string
        baseUrl:
          type:
            - 'null'
            - string
        token:
          type: string
    ConnectionCredentialsRequestOpenaiConnectionCredentialsRequest:
      required:
        - adminKey
      properties:
        connectorType:
          enum:
            - openai
          type: string
        adminKey:
          type: string
    ConnectionCredentialsRequestAnthropicConnectionCredentialsRequest:
      required:
        - adminKey
      properties:
        connectorType:
          enum:
            - anthropic
          type: string
        adminKey:
          type: string
    ConnectionCredentialsRequestOnePasswordConnectionCredentialsRequest:
      required:
        - scimUrl
        - token
      properties:
        connectorType:
          enum:
            - one_password
          type: string
        scimUrl:
          type:
            - 'null'
            - string
        token:
          type: string
    ConnectionCredentialsRequestKeeperConnectionCredentialsRequest:
      required:
        - scimUrl
        - token
      properties:
        connectorType:
          enum:
            - keeper
          type: string
        scimUrl:
          type: string
        token:
          type: string
    ConnectionCredentialsRequestBitwardenConnectionCredentialsRequest:
      required:
        - clientId
        - clientSecret
        - apiUrl
        - identityUrl
      properties:
        connectorType:
          enum:
            - bitwarden
          type: string
        clientId:
          type: string
        clientSecret:
          type: string
        apiUrl:
          type:
            - 'null'
            - string
        identityUrl:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestAtlassianConnectionCredentialsRequest:
      required:
        - orgId
        - apiKey
        - directoryId
      properties:
        connectorType:
          enum:
            - atlassian
          type: string
        orgId:
          type: string
        apiKey:
          type: string
        directoryId:
          type:
            - 'null'
            - string
    ConnectionCredentialsRequestNotionConnectionCredentialsRequest:
      required:
        - token
      properties:
        connectorType:
          enum:
            - notion
          type: string
        token:
          type: string
    ConnectionCredentialsRequestBambooHrConnectionCredentialsRequest:
      required:
        - companyDomain
        - apiKey
      properties:
        connectorType:
          enum:
            - bamboo_hr
          type: string
        companyDomain:
          type: string
        apiKey:
          type: string
    FirstSignInKind:
      enum:
        - password
        - temporary_access_pass
  securitySchemes:
    cookieAuth:
      type: apiKey
      description: >-
        Cookie-based session. Obtain by completing the `/auth/login/{provider}`
        OAuth flow; the `/auth/callback` response sets the `klef.session` cookie
        that subsequent requests send automatically.
      name: klef.session
      in: cookie
    apiKeyAuth:
      type: http
      description: >-
        An API key from **Settings > API keys**, sent as `Authorization: Bearer
        klef_sk_…`. A key works only on its own workspace's subdomain, and only
        with the permissions its scopes grant.
      scheme: bearer
      bearerFormat: klef_sk_…

````