Skip to main content
POST
Update A2A agent

Restrictions

Usage

  • Requires edit permission (access.CanEdit) on the agent’s current team before any field may change.
  • Reassigning team_id requires rights on the destination team; if the team changes without also sending a new environment binding, the existing runner binding must remain selectable by the caller or the update is rejected.
  • Changing auth_mode always rewrites secret_schema together with it; omitting oauth_metadata alongside a new auth_mode clears it to empty.
  • Sending back a masked or empty value for a sensitive auth_config key (api_key, token, client_secret) keeps the stored secret instead of overwriting it.
  • Every call is recorded in the account audit log.

Authorizations

app_key
string
query
required

App key issued from the Flashduty console. Required on every public API call. Keep it secret — it grants the same access as the owning account.

Body

application/json

Partial update of an A2A agent. A null/omitted field is left unchanged.

agent_id
string
required

Target agent ID, from the list returned by POST /safari/a2a-agent/list.

agent_name
string | null

New display name. Omit to leave unchanged.

Maximum string length: 128
instructions
string | null

New instructions document (same contract as create: optional summary frontmatter, non-empty body, at most 50 KiB). Omit to leave unchanged. A deprecated description field is also accepted; if both are sent they must match.

Maximum string length: 51200
card_url
string | null

New card URL. Omit to leave unchanged.

auth_type
enum<string> | null

New auth type: none, api_key, or bearer. Omit to leave unchanged.

Available options:
none,
api_key,
bearer
auth_config
object

Replace the whole auth config; omit to leave unchanged. Keys missing from the map are dropped. For a sensitive key, sending back the masked value keeps the stored secret, while sending an empty string clears it.

streaming
boolean | null

Toggle streaming support. Omit to leave unchanged.

team_id
integer<int64> | null

Reassign team scope. Omit to leave unchanged. Reassigning requires rights on the destination team; if the team changes without also sending a new environment binding, the existing runner binding must remain selectable by the caller or the update is rejected.

environments
string[] | null

Execution environments this agent is callable from: cloud and/or BYOC runner environment IDs. Omit (null) to leave unchanged; send a list to set it — an empty list clears the restriction back to all environments.

auth_mode
string | null

New auth mode: shared, per_user_secret, or per_user_oauth. Changing it always rewrites secret_schema together with it.

secret_schema
string | null

New JSON secret schema.

oauth_metadata
string | null

New JSON OAuth metadata. If omitted while auth_mode changes, it is cleared to empty.

allow_insecure_oauth_http
boolean | null

Toggle non-loopback HTTP OAuth discovery for this agent. Omit to leave unchanged.

allow_insecure_tls_skip_verify
boolean | null

Toggle TLS certificate verification skipping for this agent. Omit to leave unchanged.

Response

Success

Standard response envelope used by every Flashduty public API. On success data contains the endpoint-specific payload and error is absent. On failure error is present and data is absent. request_id is always present and is also mirrored in the Flashcat-Request-Id response header.

request_id
string
required

Unique ID for this request. Mirrored in the Flashcat-Request-Id header. Include it when reporting issues.

Example:

"01HK8XQE3Z7JM2NTFQ5YJ8P9R4"

error
object

Error payload inside the response envelope. Present only on non-2xx responses.

data
null

Always null on success.