> ## Documentation Index
> Fetch the complete documentation index at: https://docs.summation.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update connection settings

> Change a connection's non-secret settings without supplying its credentials.

The sibling of ``PATCH .../snapshot-config``: that route carries the snapshot policy, this
one the connector's own settings. Neither body has a ``secrets`` field, so a credential
cannot be sent, logged, or named in a generated tool schema. Data Management rebuilds the
credential set from the stored references to satisfy validators that require one (NetSuite
TBA, Snowflake, Databricks …), so a settings-only change never needs the credential resent.

Send ``if_match_updated_at`` carrying the connection's current ``updatedAt`` (from
``GET /v1/connections/data/{connection_id}``) and the write is refused with 412 if the
connection changed since: the update sends a whole config object, so without a precondition
two concurrent callers would each silently replace the other's change.

Merges rather than replaces: omitted keys keep their stored values and a null value clears
one key, except where the connection needs that key to work. Accepts only settings marked ``patchable_without_secret`` by
``GET /v1/connections/data/types/{type}`` — those that select something inside an
already-authenticated account (a database, region, port, probe path). Settings that hold a
credential, name the host, choose the auth mode, or protect the connection in transit are
refused, and stay on ``PATCH /v1/connections/data/{connection_id}`` where the caller is
expected to supply the credential matching the new target.



## OpenAPI

````yaml https://api.summation.com/openapi.json patch /v1/connections/data/{connection_id}/config
openapi: 3.1.0
info:
  title: summation-api public API
  version: 0.1.0
servers: []
security: []
tags:
  - name: Auth
    description: Machine authentication for API clients.
  - name: Tenant
    description: Organization and tenant context resolved by summation-api.
  - name: Projects
    description: Project resources.
  - name: Conversations
    description: Conversation and message resources.
  - name: Reports
    description: Report resources and report operations.
  - name: Runs
    description: Project run history and execution status.
  - name: Playbooks
    description: Playbook resources.
  - name: Files
    description: Project file resources.
  - name: Catalog Entries
    description: Project-scoped data asset attachments.
  - name: Data Connectors
    description: Reusable external data source connections.
  - name: App Connectors
    description: External app connectors whose tools the agent can use during chat.
  - name: Tables
    description: Canonical table metadata and catalog.
  - name: Views
    description: Canonical Summation view metadata and catalog.
  - name: Query Executions
    description: Read-only SQL query execution.
  - name: Grid
    description: Materialized grid status, sync, and lineage.
  - name: Schedules
    description: Schedule and schedule run inspection.
  - name: Workflows
    description: >-
      Workflows: what they run, when they run, and where their output is
      delivered.
  - name: Verification Tests
    description: >-
      Administrative custom verification-test definitions, overlays, and
      effective-set previews.
paths:
  /v1/connections/data/{connection_id}/config:
    patch:
      tags:
        - Data Connectors
      summary: Update connection settings
      description: >-
        Change a connection's non-secret settings without supplying its
        credentials.


        The sibling of ``PATCH .../snapshot-config``: that route carries the
        snapshot policy, this

        one the connector's own settings. Neither body has a ``secrets`` field,
        so a credential

        cannot be sent, logged, or named in a generated tool schema. Data
        Management rebuilds the

        credential set from the stored references to satisfy validators that
        require one (NetSuite

        TBA, Snowflake, Databricks …), so a settings-only change never needs the
        credential resent.


        Send ``if_match_updated_at`` carrying the connection's current
        ``updatedAt`` (from

        ``GET /v1/connections/data/{connection_id}``) and the write is refused
        with 412 if the

        connection changed since: the update sends a whole config object, so
        without a precondition

        two concurrent callers would each silently replace the other's change.


        Merges rather than replaces: omitted keys keep their stored values and a
        null value clears

        one key, except where the connection needs that key to work. Accepts
        only settings marked ``patchable_without_secret`` by

        ``GET /v1/connections/data/types/{type}`` — those that select something
        inside an

        already-authenticated account (a database, region, port, probe path).
        Settings that hold a

        credential, name the host, choose the auth mode, or protect the
        connection in transit are

        refused, and stay on ``PATCH /v1/connections/data/{connection_id}``
        where the caller is

        expected to supply the credential matching the new target.
      operationId: update_data_connection_config
      parameters:
        - name: connection_id
          in: path
          required: true
          schema:
            type: string
            title: Connection Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectionConfigUpdateRequest'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid request or unsupported option.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
        '401':
          description: Missing, invalid, or expired credentials.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
        '403':
          description: Authenticated but missing the required scope.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
        '404':
          description: Resource not found or not accessible.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: Rate limit exceeded.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
        '500':
          description: Internal server error.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemError'
      security:
        - SummationMachineAuth:
            - agent:write
components:
  schemas:
    ConnectionConfigUpdateRequest:
      properties:
        if_match_updated_at:
          anyOf:
            - type: string
            - type: 'null'
          title: If Match Updated At
          description: >-
            The connection's current updatedAt, from GET
            /v1/connections/data/{connection_id}. When given, this write is
            refused with 412 if the connection changed since that read, so it
            cannot overwrite an edit made in between. Omitted, the write applies
            unconditionally.
        config:
          additionalProperties: true
          type: object
          title: Config
          description: >-
            Settings to change, MERGED into the stored config — omitted keys
            keep their values, and a null value clears one key. (Unlike
            snapshot_config, which replaces in full.) Only settings that neither
            hold a credential nor change how the connection authenticates are
            accepted; GET /v1/connections/data/types/{type} marks each one
            patchable_without_secret. Re-pointing the connection at a different
            host, changing its auth mode, or weakening its transport security
            stay on the credentialed route.
          examples:
            - health_probe: /services/rest/record/v1/metadata-catalog
      additionalProperties: false
      type: object
      required:
        - config
      title: ConnectionConfigUpdateRequest
      description: >-
        Non-secret connector settings on their own, with no field that can carry
        a credential.


        The sibling of ``ConnectionSnapshotConfigRequest``: that one carries the
        snapshot policy,

        this one the connector's own settings. Both exist because the combined
        connection PATCH

        accepts ``secrets`` and so stays off the agent surface — which also
        withheld settings that

        hold no credential at all, such as an HTTP connection's
        ``health_probe``.


        Which keys are accepted is not written here: it is
        ``ConnectorField.patchable_without_secret``

        in the connector registry, so the answer travels with the field
        definition rather than a

        list that a rename could silently fall out of.
    ProblemError:
      description: >-
        Public error envelope (RFC 7807 ``application/problem+json``).


        Mirrors the body produced by :func:`api_error`. Declaring it in the
        contract

        lets generated clients type error handling instead of guessing.
      properties:
        type:
          description: URI reference identifying the problem type.
          title: Type
          type: string
        title:
          description: Short, human-readable summary of the problem type.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation specific to this occurrence.
          title: Detail
          type: string
        code:
          description: Stable, machine-readable error code.
          title: Code
          type: string
        request_id:
          description: Correlation id, echoed in the x-request-id header.
          title: Request Id
          type: string
      required:
        - type
        - title
        - status
        - detail
        - code
        - request_id
      title: ProblemError
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    SummationMachineAuth:
      type: oauth2
      flows:
        clientCredentials:
          scopes:
            agent:read: agent:read
            agent:write: agent:write
          tokenUrl: /v1/auth/m2m/token

````