> ## Documentation Index
> Fetch the complete documentation index at: https://infisical-platfor-532.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Update



## OpenAPI

````yaml PATCH /api/v3/gateways/{gatewayId}
openapi: 3.0.3
info:
  title: Infisical API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
  - url: https://us.infisical.com
    description: Production server (US)
  - url: https://eu.infisical.com
    description: Production server (EU)
  - url: http://localhost:8080
    description: Local server
security: []
paths:
  /api/v3/gateways/{gatewayId}:
    patch:
      tags:
        - Gateways
      operationId: updateGateway
      parameters:
        - schema:
            type: string
            format: uuid
          in: path
          name: gatewayId
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                authMethod:
                  anyOf:
                    - type: object
                      properties:
                        method:
                          type: string
                          enum:
                            - aws
                        stsEndpoint:
                          type: string
                          minLength: 1
                          maxLength: 255
                          default: https://sts.amazonaws.com/
                          description: The endpoint URL for the AWS STS API.
                        allowedPrincipalArns:
                          type: string
                          maxLength: 4096
                          default: ''
                          description: >-
                            The comma-separated list of trusted IAM principal
                            ARNs that are allowed to authenticate with
                            Infisical.
                        allowedAccountIds:
                          type: string
                          maxLength: 4096
                          default: ''
                          description: >-
                            The comma-separated list of trusted AWS account IDs
                            that are allowed to authenticate with Infisical.
                      required:
                        - method
                      additionalProperties: false
                    - type: object
                      properties:
                        method:
                          type: string
                          enum:
                            - kubernetes
                        kubernetesHost:
                          type: string
                          minLength: 1
                          maxLength: 255
                          description: >-
                            The URL of the Kubernetes API server that Infisical
                            reviews the gateway's service account token against
                            (e.g. https://my-cluster.example.com:6443). Omit
                            only when tokenReviewMode is 'gateway', where the
                            reviewing gateway calls its own API server.
                        caCertificate:
                          type: string
                          maxLength: 10240
                          description: >-
                            The PEM-encoded CA certificate that issued the
                            Kubernetes API server's TLS certificate. Required
                            when the API server uses a certificate the system
                            trust store does not recognise, which is the usual
                            case for a cluster CA.
                        tokenReviewerJwt:
                          type: string
                          maxLength: 8192
                          description: >-
                            A long-lived service account token with the
                            system:auth-delegator ClusterRole used to submit
                            TokenReview requests. Omit to have the gateway's own
                            token act as the reviewer. Write-only: never
                            returned by the API.
                        tokenReviewMode:
                          type: string
                          enum:
                            - api
                            - gateway
                          default: api
                          description: >-
                            Who performs the TokenReview. 'api' means Infisical
                            does, using the configured token reviewer JWT.
                            'gateway' means the selected gateway does, using its
                            own in-cluster service account, which requires no
                            Kubernetes host or reviewer token but requires that
                            gateway to run as a pod in the cluster.
                        gatewayId:
                          type: string
                          format: uuid
                          nullable: true
                          description: >-
                            The gateway to route TokenReview traffic through,
                            for clusters whose API server Infisical cannot
                            reach. Must be a different gateway that is already
                            enrolled and connected. Mutually exclusive with
                            gatewayPoolId.
                        gatewayPoolId:
                          type: string
                          format: uuid
                          nullable: true
                          description: >-
                            The gateway pool to route TokenReview traffic
                            through. Any healthy member performs the request, so
                            this survives a single gateway going offline.
                            Mutually exclusive with gatewayId.
                        allowedNamespaces:
                          type: string
                          maxLength: 1024
                          description: >-
                            The comma-separated list of Kubernetes namespaces
                            whose service accounts are allowed to authenticate
                            as this gateway. Supports `*` wildcards.
                        allowedNames:
                          type: string
                          maxLength: 1024
                          description: >-
                            The comma-separated list of Kubernetes service
                            account names that are allowed to authenticate as
                            this gateway. Supports `*` wildcards.
                        allowedAudience:
                          type: string
                          maxLength: 255
                          default: ''
                          description: >-
                            The audience the gateway's service account token
                            must carry. Leave empty to skip the audience check.
                        verifyTlsCertificate:
                          type: boolean
                          default: true
                          description: >-
                            Whether to verify the Kubernetes API server's TLS
                            certificate. Verified against the CA certificate
                            when one is configured, otherwise against the system
                            trust store.
                      required:
                        - method
                        - allowedNamespaces
                        - allowedNames
                      additionalProperties: false
                    - type: object
                      properties:
                        method:
                          type: string
                          enum:
                            - token
                      required:
                        - method
                      additionalProperties: false
                  description: >-
                    Replacement auth method. Same shape as in create: `aws` with
                    allowlists, `kubernetes` with cluster config, or `token`
                    with no config. Existing gateways keep working until they
                    restart and re-authenticate via the new method.
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    format: uuid
                  identityId:
                    type: string
                    format: uuid
                    nullable: true
                  name:
                    type: string
                  createdAt:
                    type: string
                    format: date-time
                  updatedAt:
                    type: string
                    format: date-time
                  heartbeat:
                    type: string
                    format: date-time
                    nullable: true
                  heartbeatTTL:
                    type: number
                    nullable: true
                  canRevoke:
                    type: boolean
                  authMethod:
                    anyOf:
                      - type: object
                        properties:
                          method:
                            type: string
                            enum:
                              - aws
                          config:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                              stsEndpoint:
                                type: string
                              allowedPrincipalArns:
                                type: string
                              allowedAccountIds:
                                type: string
                              createdAt:
                                type: string
                                format: date-time
                              updatedAt:
                                type: string
                                format: date-time
                            required:
                              - id
                              - stsEndpoint
                              - allowedPrincipalArns
                              - allowedAccountIds
                              - createdAt
                              - updatedAt
                            additionalProperties: false
                        required:
                          - method
                          - config
                        additionalProperties: false
                      - type: object
                        properties:
                          method:
                            type: string
                            enum:
                              - kubernetes
                          config:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                              kubernetesHost:
                                type: string
                              tokenReviewMode:
                                type: string
                              gatewayId:
                                type: string
                                nullable: true
                              gatewayPoolId:
                                type: string
                                nullable: true
                              allowedNamespaces:
                                type: string
                              allowedNames:
                                type: string
                              allowedAudience:
                                type: string
                              verifyTlsCertificate:
                                type: boolean
                              caCertificate:
                                type: string
                              hasTokenReviewerJwt:
                                type: boolean
                              createdAt:
                                type: string
                                format: date-time
                              updatedAt:
                                type: string
                                format: date-time
                            required:
                              - id
                              - kubernetesHost
                              - tokenReviewMode
                              - gatewayId
                              - gatewayPoolId
                              - allowedNamespaces
                              - allowedNames
                              - allowedAudience
                              - verifyTlsCertificate
                              - caCertificate
                              - hasTokenReviewerJwt
                              - createdAt
                              - updatedAt
                            additionalProperties: false
                        required:
                          - method
                          - config
                        additionalProperties: false
                      - type: object
                        properties:
                          method:
                            type: string
                            enum:
                              - token
                          config:
                            type: object
                            properties: {}
                            additionalProperties: false
                        required:
                          - method
                          - config
                        additionalProperties: false
                      - type: object
                        properties:
                          method:
                            type: string
                            enum:
                              - identity
                          config:
                            type: object
                            properties:
                              identityId:
                                type: string
                              identityName:
                                type: string
                                nullable: true
                            required:
                              - identityId
                              - identityName
                            additionalProperties: false
                        required:
                          - method
                          - config
                        additionalProperties: false
                required:
                  - id
                  - name
                  - createdAt
                  - updatedAt
                  - canRevoke
                  - authMethod
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 422
                  message: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false

````