Skip to main content
PUT
Create or replace a cloud access connection

Authorizations

Authorization
string
header
required

Your Reason API key from Settings > API. New keys use reason_; legacy ara_ keys remain accepted. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:read reads sessions, including the assistant, reasoning and tool activity in their events. sessions:debug is privileged: only for organization owners/admins, it expands session events to the full diagnostic projection (diagnostic event kinds, status text and raw event metadata).

Path Parameters

orgId
string
required

Organization id or slug. Resolve it with GET /v3/self.

provider
enum<string>
required

The cloud access provider.

Available options:
aws,
gcp,
azure

Body

application/json
config
object
required

Provider identifiers, as in the connection.

enabled
boolean
allowed_triggers
enum<string>[]
Minimum array length: 1
Available options:
manual,
api,
schedule,
github_event,
webhook,
slack,
linear

Response

The saved connection.

provider
enum<string>
required
Available options:
aws,
gcp,
azure
config
object
required

Provider identifiers: aws role_arn, region; gcp workload_identity_provider, service_account, project_id; azure tenant_id, client_id, subscription_id.

enabled
boolean
required
allowed_triggers
enum<string>[]
required

Run triggers this connection signs in.

Available options:
manual,
api,
schedule,
github_event,
webhook,
slack,
linear
updated_at
string<date-time>
required
last_tested_at
string<date-time> | null
last_test_ok
boolean | null
last_test_message
string | null
last_used_at
string<date-time> | null