Skip to the page
Chapters

SFTP account

Rotate the SFTP password

POST/api/v1/sftp-account/rotate-password

Replaces the account's password with a new generated one: the old one stops working for every new login at once. A session already open stays open until the client disconnects or has been idle 15 minutes. Send an empty JSON object as the body. The response carries the password (password). It is shown only in this response and cannot be read again: store it now. A request repeated with the same Idempotency-Key gets the stored reply without the password (password_available is false): rotate the password to get a new one. Needs an Idempotency-Key header and a key with the submit permission.

Needs a key with submit permission.

Request

Headers

Headers
NameTypeRequiredDescription
Idempotency-KeystringrequiredMakes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`.

Response

The account, with its new password. Status 200.

Response fields
NameTypeDescription
idstringAn ID that starts with sftp_.
objectstringAlways `sftp_account`.
statusstringA disabled account is refused at login; its files stay where they are.One of: `active`, `disabled`.
usernamestringThe user name to log in with.
hostvalueThe host to connect to; null in an environment that has no SFTP host.
portinteger or nullThe port to connect to; null in an environment that has no SFTP host.At least -9007199254740991.
host_key_fingerprintvalueThe SHA256 fingerprint of the server's host key: check it the first time you connect. Null in an environment that has no SFTP host.
foldersobjectThe folders of the account. A file dropped in a folder under TEST is a test file; the folder is the mode.
folders.testobject
folders.test.instringAlways `TEST/IN`.
folders.test.outstringAlways `TEST/OUT`.
folders.liveobject
folders.live.instringAlways `IN`.
folders.live.outstringAlways `OUT`.
keysarray of objectThe public keys that may log in, at most 5.At most 5 items.
keys[].idstringAn ID that starts with sfk_.
keys[].objectstringAlways `sftp_key`.
keys[].labelstringThe name you gave the key.At most 64 characters.
keys[].fingerprintstringThe key's SHA256 fingerprint, as ssh-keygen -l shows it.
keys[].added_atstring (date-time)
last_login_atstring (date-time) or null
last_file_atstring (date-time) or nullWhen the last file dropped on the account was taken.
created_atstring (date-time)
passwordstringThe password to log in with. Shown only in the response that made it: store it now. Absent when password_available is false.
password_availablebooleanFalse in the stored reply an Idempotency-Key replay returns: the password is never stored for replay. Rotate the password to get a new one.

Errors

Errors
HTTP statusCodeWhat it means
401UNAUTHORIZEDA valid API key is required. Send it as "Authorization: Bearer <key>".
403PERMISSION_DENIEDThis API key is not allowed to do that.
404NOT_FOUNDNot found.
422INVALID_REQUESTThe request is not valid.
400IDEMPOTENCY_KEY_REQUIREDPOST and PATCH requests need an Idempotency-Key header.
422IDEMPOTENCY_KEY_REUSEDThat Idempotency-Key was already used with a different request.
409IDEMPOTENCY_KEY_IN_USEA request with that Idempotency-Key is still running. Retry shortly.
413PAYLOAD_TOO_LARGEThe request body is larger than 1 MB.
504TIMEOUTThe request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission).
500INTERNALSomething went wrong on our side. Quote the request ID if you contact us.

Example

Example request

Shell
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/sftp-account/rotate-password" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{}'

Example response: 200

JSON
{
  "id": "sftp_01JM000000E00800000000008G",
  "object": "sftp_account",
  "status": "active",
  "username": "example-dental-group",
  "host": "sftp.example.com",
  "port": 22,
  "host_key_fingerprint": "SHA256:3rJq0nX1m2Yw8dVf5uQ7bT9kLz4cE6hA1sPoGvNxYdI",
  "folders": {
    "test": {
      "in": "TEST/IN",
      "out": "TEST/OUT"
    },
    "live": {
      "in": "IN",
      "out": "OUT"
    }
  },
  "keys": [
    {
      "id": "sfk_01JM000000E00800000000008H",
      "object": "sftp_key",
      "label": "Billing server",
      "fingerprint": "SHA256:Nn0vBzE3Lx9sT2kqYw7dPfH5cRj8uAm1GoVtXiQ4eZs",
      "added_at": "2026-09-24T15:05:00+00:00"
    }
  ],
  "last_login_at": "2026-09-24T21:00:00+00:00",
  "last_file_at": "2026-09-24T21:01:00+00:00",
  "created_at": "2026-09-24T15:00:00+00:00",
  "password": "k3Vq9xT1mZ8wRb4nJc7YdLfH2sGpA6uE",
  "password_available": true
}