> ## Documentation Index
> Fetch the complete documentation index at: https://docs.valendata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a login's fields

> Send a new password, username or authenticator seed. Nothing secret comes back.

Send `"totp_secret": ""` to remove the authenticator seed.


## OpenAPI

````yaml PATCH /v1/logins/{login_id}
openapi: 3.0.3
info:
  title: Valendata REST API
  version: 1.0.0
  description: >-
    Trigger Skills, manage Workflows, retrieve Runs, and stream structured
    results from any language using JSON over HTTPS.
servers:
  - url: https://api.valendata.com
    description: Production
security:
  - ApiKeyAuth: []
tags:
  - name: Skills
    description: Execute and inspect published Skills.
  - name: Workflows
    description: Trigger multi-step Workflows and list them.
  - name: Runs
    description: Start async Skill runs and read Skill and Workflow run results.
  - name: Skill creation
    description: Create a Skill from a plain-language task.
  - name: Skill improvement
    description: >-
      Fix a Skill, add fields to it or re-learn its detail steps, poll the
      result, and read its change history.
  - name: Versions
    description: List, diff, restore, and pin a Skill's recipe versions.
  - name: Webhooks
    description: Signed delivery of finished async runs.
paths:
  /v1/logins/{login_id}:
    patch:
      tags:
        - Logins
      summary: Replace a login's fields
      description: >-
        Send a new password, username or authenticator seed. Nothing secret
        comes back.
      operationId: updateLogin
      parameters:
        - name: login_id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateLoginRequest'
      responses:
        '200':
          description: The masked login.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Login'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    UpdateLoginRequest:
      type: object
      description: >-
        Every field is optional; the ones you send replace the stored value.
        `totp_secret: ""` removes the seed.
      properties:
        site:
          type: string
          description: The site's domain or a URL on it.
          example: the-internet.herokuapp.com
          nullable: true
        username:
          type: string
          maxLength: 320
          nullable: true
        password:
          type: string
          maxLength: 1024
          description: Stored encrypted. Never returned by any endpoint.
          nullable: true
        totp_secret:
          type: string
          nullable: true
          description: >-
            Authenticator seed (base32, or the whole otpauth:// URI) for sites
            that ask for an app code. Never returned.
        label:
          type: string
          nullable: true
          maxLength: 120
        notes:
          type: string
          nullable: true
          maxLength: 500
    Login:
      type: object
      description: >-
        A saved login as every endpoint shows it. Never the password, seed or a
        code.
      properties:
        id:
          type: string
        site:
          type: string
          nullable: true
        username_hint:
          type: string
          example: to***h
        label:
          type: string
        notes:
          type: string
          nullable: true
        has_totp:
          type: boolean
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    Error:
      type: object
      properties:
        detail:
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
          description: >-
            Error message. Usually a plain string; may be a structured object
            for some errors.
      example:
        detail: Invalid or expired API key
  responses:
    Unauthorized:
      description: >-
        Unauthorized. The Authorization header is missing, malformed, or the
        credential is invalid or expired.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        Forbidden. You may not run or change this Skill, or it is not published
        or active.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: Resource not found in your Workspace.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: vd_sk_...
      description: >-
        API key with the `vd_sk_` prefix. Create keys from Settings, API Keys in
        the dashboard.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.