> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qoder.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a Session resource

> Rotate a GitHub repository resource token.

`POST /api/v1/cloud/sessions/{session_id}/resources/{resource_id}`

Updates one Session resource. Current CAS supports token rotation only for `github_repository` resources.

## Path parameters

| Parameter     | Type   | Description                         |
| ------------- | ------ | ----------------------------------- |
| `session_id`  | string | Session ID with the `sess_` prefix  |
| `resource_id` | string | Resource ID with the `sesr_` prefix |

## Headers

| Header          | Required | Description         |
| --------------- | -------- | ------------------- |
| `Authorization` | Yes      | `Bearer $QODER_PAT` |
| `Content-Type`  | Yes      | `application/json`  |

## Request body

| Field                 | Type   | Required | Description      |
| --------------------- | ------ | -------- | ---------------- |
| `authorization_token` | string | Yes      | New GitHub token |

## Example request

```bash theme={null}
curl -X POST https://api.qoder.com/api/v1/cloud/sessions/sess_019e392c0d1e74e095d21ea4c6b41def/resources/sesr_0e4323e8f47ba34853f5409e \
  -H "Authorization: Bearer $QODER_PAT" \
  -H "Content-Type: application/json" \
  -d '{"authorization_token":"ghp_newtoken"}'
```

## Example response

**HTTP 200 OK**

Returns the updated [Session resource](/cloud-agents/api/sessions/schemas#session-resource). The token is not returned.

```json theme={null}
{
  "id": "sesr_0e4323e8f47ba34853f5409e",
  "type": "github_repository",
  "url": "https://github.com/your-org/your-repo",
  "mount_path": "/data/workspace/your-repo",
  "checkout": {"type": "branch", "name": "main"},
  "created_at": "2026-06-23T05:53:19.774840Z",
  "updated_at": "2026-06-23T06:01:42.124501Z"
}
```

## Errors

| HTTP | Type                    | Trigger                                                     |
| ---- | ----------------------- | ----------------------------------------------------------- |
| 400  | `invalid_request_error` | Resource is not a `github_repository`, or malformed request |
| 401  | `authentication_error`  | PAT invalid or expired                                      |
| 404  | `not_found_error`       | Session or resource does not exist                          |

**HTTP 400 Bad Request**

```json theme={null}
{
  "type": "error",
  "request_id": "cb80235f-76a2-4ff3-9e28-5aa2da12dc14",
  "error": {
    "type": "invalid_request_error",
    "message": "Field 'authorization_token' is required."
  }
}
```

**HTTP 404 Not Found**

```json theme={null}
{
  "type": "error",
  "request_id": "cb80235f-76a2-4ff3-9e28-5aa2da12dc14",
  "error": {
    "type": "not_found_error",
    "message": "Session resource 'sesr_does_not_exist_xxxxxxxxxxxxxxxxxxxxxxx' was not found."
  }
}
```

**HTTP 404 Not Found**

```json theme={null}
{
  "type": "error",
  "request_id": "cb80235f-76a2-4ff3-9e28-5aa2da12dc14",
  "error": {
    "type": "not_found_error",
    "message": "Session 'sess_does_not_exist_xxxxxxxxxxxxxxxxxxxxxxx' was not found."
  }
}
```

See [Errors](/cloud-agents/api/conventions/errors) for the full error envelope.
