> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a Session Resource

> Replaces the write-only authorization token for one GitHub repository Resource and returns its updated public snapshot. File and MemoryStore Resources do not support this operation, and the token is never returned or recorded in Session events.

Checkfu support posture: alpha; hosted. Required evidence journey: session-turn. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json post /v1/sessions/{session_id}/resources/{resource_id}
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: sandboxProfiles
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/sessions/{session_id}/resources/{resource_id}:
    post:
      tags:
        - sessions
      summary: Update a Session Resource
      description: >-
        Replaces the write-only authorization token for one GitHub repository
        Resource and returns its updated public snapshot. File and MemoryStore
        Resources do not support this operation, and the token is never returned
        or recorded in Session events.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        session-turn. Deployment-specific readiness and the latest proven
        release are available from GET /v1/support/capabilities.
      operationId: sessions.updateSessionResource
      parameters:
        - name: session_id
          in: path
          schema:
            $ref: '#/components/schemas/SessionId'
          required: true
        - name: resource_id
          in: path
          schema:
            $ref: '#/components/schemas/SessionResourceId'
          required: true
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
        - name: checkfu-beta
          in: header
          schema:
            $ref: '#/components/schemas/ManagedAgentsBetaHeaderValue'
          required: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/BetaManagedAgentsSessionResourceUpdateParams
        required: true
      responses:
        '200':
          description: BetaManagedAgentsSessionResource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BetaManagedAgentsSessionResource'
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationMalformedError'
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '409':
          description: The operation is illegal for the resource's current lifecycle state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInvalidTransitionError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    SessionId:
      type: string
      allOf:
        - pattern: ^sess_[0-9a-f]{32}$
    SessionResourceId:
      type: string
      allOf:
        - pattern: ^sesrsc_[0-9a-f]{32}$
    ManagedAgentsBetaHeaderValue:
      type: string
    BetaManagedAgentsSessionResourceUpdateParams:
      type: object
      properties:
        authorization_token:
          type: string
      required:
        - authorization_token
      additionalProperties: false
    BetaManagedAgentsSessionResource:
      anyOf:
        - $ref: '#/components/schemas/BetaManagedAgentsGitHubRepositoryResource'
        - $ref: '#/components/schemas/BetaManagedAgentsFileResource'
        - $ref: '#/components/schemas/BetaManagedAgentsMemoryStoreResource'
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    ValidationMalformedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.malformed
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-malformed
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The request could not be decoded or violated a declared input
        constraint.
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    RuntimeInvalidTransitionError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.invalid_transition
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#runtime-invalid-transition
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The operation is illegal for the resource's current lifecycle state.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    BetaManagedAgentsGitHubRepositoryResource:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/SessionResourceId'
        created_at:
          $ref: '#/components/schemas/CurrentTimestamp'
        updated_at:
          $ref: '#/components/schemas/CurrentTimestamp'
        mount_path:
          $ref: '#/components/schemas/CurrentMountPath'
        type:
          type: string
          enum:
            - github_repository
        url:
          $ref: '#/components/schemas/BetaManagedAgentsGitHubRepositoryUrl'
        checkout:
          anyOf:
            - $ref: '#/components/schemas/BetaManagedAgentsRepositoryCheckout'
            - type: 'null'
      required:
        - id
        - created_at
        - updated_at
        - mount_path
        - type
        - url
      additionalProperties: false
    BetaManagedAgentsFileResource:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/SessionResourceId'
        created_at:
          $ref: '#/components/schemas/CurrentTimestamp'
        updated_at:
          $ref: '#/components/schemas/CurrentTimestamp'
        file_id:
          $ref: '#/components/schemas/FileId'
        mount_path:
          $ref: '#/components/schemas/CurrentMountPath'
        type:
          type: string
          enum:
            - file
      required:
        - id
        - created_at
        - updated_at
        - file_id
        - mount_path
        - type
      additionalProperties: false
    BetaManagedAgentsMemoryStoreResource:
      type: object
      properties:
        memory_store_id:
          $ref: '#/components/schemas/MemoryStoreId'
        type:
          type: string
          enum:
            - memory_store
        access:
          anyOf:
            - type: string
              enum:
                - read_write
                - read_only
            - type: 'null'
        description:
          type: string
        instructions:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 4096
            - type: 'null'
        mount_path:
          anyOf:
            - $ref: '#/components/schemas/CurrentMountPath'
            - type: 'null'
        name:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - memory_store_id
        - type
      additionalProperties: false
    CurrentTimestamp:
      type: string
      allOf:
        - maxLength: 24
        - pattern: ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z$
          description: A canonical UTC ISO-8601 timestamp with millisecond precision.
    CurrentMountPath:
      type: string
      allOf:
        - minLength: 2
        - maxLength: 1024
    BetaManagedAgentsGitHubRepositoryUrl:
      type: string
    BetaManagedAgentsRepositoryCheckout:
      anyOf:
        - type: object
          properties:
            type:
              type: string
              enum:
                - branch
            name:
              type: string
              allOf:
                - minLength: 1
          required:
            - type
            - name
          additionalProperties: false
        - type: object
          properties:
            type:
              type: string
              enum:
                - commit
            sha:
              type: string
              allOf:
                - pattern: ^[0-9a-f]{40}$
          required:
            - type
            - sha
          additionalProperties: false
    FileId:
      type: string
      allOf:
        - pattern: ^file_[0-9a-f]{32}$
    MemoryStoreId:
      type: string
      allOf:
        - pattern: ^memstore_[0-9a-f]{32}$
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````