post
https://partner.gupshup.io/partner/app//bizai/agent_connectors//upsertCertificate
PEM-encoded. client_key may be PKCS8, RSA or EC. The private key is never returned.
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…
Request parameters
| Parameter | Type | Required | In | Description |
|---|---|---|---|---|
Authorization | string | Yes | Header | Partner app token, sent raw. Bearer <token> is also accepted. |
Content-Type | string | Yes | Header | application/json |
appId | string (uuid) | Yes | Path | Partner Portal app id. Stands in for Meta's entity_id. |
connectorId | string | Yes | Path | Connector id (pfbid). Meta pfbid… id. |
client_certificate | string | Yes | Body | PEM |
client_key | string | Yes | Body | PEM: PKCS8, RSA or EC Write-only; never returned. |
ca_certificate | string | No | Body | Optional PEM CA chain |
Example request
curl --location --request POST 'https://partner.gupshup.io/partner/app/<appId>/bizai/agent_connectors/<connectorId>/upsertCertificate' \
--header 'Authorization: <PARTNER_APP_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"client_certificate": "-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----",
"client_key": "-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----",
"ca_certificate": "-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----"
}'Response parameters — 200
200| Parameter | Type | Description |
|---|---|---|
id | string | Resource id. Meta pfbid… id. |
name | string | Name. |
description | string | Human-readable description. |
base_url | string | Root URL the connector calls. |
connector_protocol | string | One of: HTTP, MCP. |
auth_type | string | One of: OAUTH2_CLIENT_CREDENTIALS, API_KEY, NONE. |
auth_config | object | Credentials for the chosen auth_type. |
user_auth_injection_config | object | Where the consumer's own auth token is injected on outbound calls. |
user_auth_injection_config.location | string | One of: body, headers, path, query. |
user_auth_injection_config.field_name | string | Header, query or body field name. |
user_auth_injection_config.prefix | string | Text placed before the value, e.g. Bearer . |
connection_status | object | Whether the connector's credentials work. |
connection_status.status | string | One of: PENDING_OAUTH, ACTIVE, EXPIRED, ERROR. |
connection_status.error_message | string | Error text. |
mcp_tool_sync | object / null | Null for HTTP connectors. |
mcp_tool_sync.status | string | One of: ERROR, PENDING, READY. |
mcp_tool_sync.last_attempted_at | integer | Last attempt, Unix seconds. |
mcp_tool_sync.last_successful_at | integer | Last success, Unix seconds. |
mcp_tool_sync.fingerprint | string | Hash identifying the stored value. |
mcp_tool_sync.tool_count | integer | Number of tools discovered. |
mtls_config | object | Client certificate status. The private key is never returned. |
mtls_config.has_certificate | boolean | true if a certificate is stored. |
mtls_config.fingerprint | string | Hash identifying the stored value. |
mtls_config.expires_at | integer | Expiry, Unix seconds. |
mtls_config.subject | string | Certificate subject. |
mtls_config.client_certificate | string | Stored client certificate, PEM. |
mtls_config.ca_certificate | string | Stored CA chain, PEM. |
Example response — 200 OK
200 OK{
"id": "pfbid0ConnectorExampleId",
"name": "Shopify Order Management",
"description": "Connects to Shopify API for managing customer orders and inventory",
"base_url": "https://api.shopify.com",
"connector_protocol": "HTTP",
"auth_type": "API_KEY",
"auth_config": {
"api_key": {
"headers": [
{
"field_name": "X-Shopify-Access-Token",
"prefix": ""
}
]
}
},
"connection_status": {
"status": "ACTIVE"
},
"mcp_tool_sync": null,
"mtls_config": {
"has_certificate": true,
"fingerprint": "sha256:3f1e2d4c",
"expires_at": 1821166852,
"subject": "CN=api.example.com"
}
}Error responses
400 Bad Request — The app is not live, or WASS does not consider it live.
{
"message": "App is not live.",
"status": "error"
}400 Bad Request — The app has no phone number attached. Checked before the live check.
{
"message": "Phone id not found for the given App",
"status": "error"
}401 Unauthorized — Authorization is missing or invalid, belongs to another app, or appId is unknown or not a UUID.
{
"status": "error",
"message": "Unauthorised access to the resource. Please review request parameters and headers and retry"
}405 Method Not Allowed — Any method other than GET, POST, PUT or DELETE, e.g. PATCH.
{
"status": "error",
"message": "Request method 'PATCH' is not supported"
}429 Too Many Requests — More than 30 /bizai/** requests in 60 seconds for this app. The 31st is rejected.
{
"status": "error",
"message": "Too Many Requests"
} 429Per-app rate limit exceeded. Retry after the 60-second window.
