curl --request PATCH \
--url https://api.nexspace365.com/api/credentials/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"type": "<string>",
"name": "<string>",
"issuer": "<string>",
"issueDate": "2023-12-25",
"expirationDate": "2023-12-25",
"fileUrl": "<string>"
}
'import requests
url = "https://api.nexspace365.com/api/credentials/{id}"
payload = {
"type": "<string>",
"name": "<string>",
"issuer": "<string>",
"issueDate": "2023-12-25",
"expirationDate": "2023-12-25",
"fileUrl": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
type: '<string>',
name: '<string>',
issuer: '<string>',
issueDate: '2023-12-25',
expirationDate: '2023-12-25',
fileUrl: '<string>'
})
};
fetch('https://api.nexspace365.com/api/credentials/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nexspace365.com/api/credentials/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'type' => '<string>',
'name' => '<string>',
'issuer' => '<string>',
'issueDate' => '2023-12-25',
'expirationDate' => '2023-12-25',
'fileUrl' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nexspace365.com/api/credentials/{id}"
payload := strings.NewReader("{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.nexspace365.com/api/credentials/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nexspace365.com/api/credentials/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": 7,
"userId": 42,
"type": "certification",
"name": "Forklift Operator Certification",
"issuer": "National Safety Council",
"issueDate": "2024-06-01",
"expirationDate": "2027-06-01",
"status": "active",
"fileUrl": "https://files.nexspace365.com/creds/7.pdf"
}{
"error": {
"message": "Invalid or revoked API key",
"code": "UNAUTHENTICATED",
"suggestion": "Send a valid `Authorization: Bearer <token>` (nex_live_/nex_pat_ key, JWT, or OAuth access token).",
"retryable": false
}
}{
"error": {
"message": "<string>",
"code": "<string>",
"details": {},
"suggestion": "<string>",
"retryable": true
},
"requestId": "<string>"
}{
"error": {
"message": "<string>",
"code": "<string>",
"details": {},
"suggestion": "<string>",
"retryable": true
},
"requestId": "<string>"
}{
"error": {
"message": "Rate limit exceeded for this API key",
"code": "API_KEY_RATE_LIMITED",
"suggestion": "Wait until X-RateLimit-Reset before retrying, or batch operations.",
"retryable": true
}
}Update a credential
Update a single credential by its own id.
Note the prefix. Listing and creating credentials happens under the
staff member (GET/POST /api/staff/{id}/credentials, where {id} is
the staff id). Updating and deleting one happens here, under
/api/credentials/{id}, where {id} is the credential id. Two
different prefixes for one resource — a client that assumes
PATCH /api/staff/{id}/credentials/{credentialId} will 404.
Known limitation: the handler forwards the merged body to the storage layer’s credential insert, so today this writes a new credential row rather than updating the existing one. Treat it as unstable and prefer re-creating the credential until that is fixed.
Requires staff.manage_credentials, which an API key satisfies through
the write action alias. Required API-key scope: staff:write
curl --request PATCH \
--url https://api.nexspace365.com/api/credentials/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"type": "<string>",
"name": "<string>",
"issuer": "<string>",
"issueDate": "2023-12-25",
"expirationDate": "2023-12-25",
"fileUrl": "<string>"
}
'import requests
url = "https://api.nexspace365.com/api/credentials/{id}"
payload = {
"type": "<string>",
"name": "<string>",
"issuer": "<string>",
"issueDate": "2023-12-25",
"expirationDate": "2023-12-25",
"fileUrl": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
type: '<string>',
name: '<string>',
issuer: '<string>',
issueDate: '2023-12-25',
expirationDate: '2023-12-25',
fileUrl: '<string>'
})
};
fetch('https://api.nexspace365.com/api/credentials/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nexspace365.com/api/credentials/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'type' => '<string>',
'name' => '<string>',
'issuer' => '<string>',
'issueDate' => '2023-12-25',
'expirationDate' => '2023-12-25',
'fileUrl' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nexspace365.com/api/credentials/{id}"
payload := strings.NewReader("{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.nexspace365.com/api/credentials/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nexspace365.com/api/credentials/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": \"<string>\",\n \"name\": \"<string>\",\n \"issuer\": \"<string>\",\n \"issueDate\": \"2023-12-25\",\n \"expirationDate\": \"2023-12-25\",\n \"fileUrl\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": 7,
"userId": 42,
"type": "certification",
"name": "Forklift Operator Certification",
"issuer": "National Safety Council",
"issueDate": "2024-06-01",
"expirationDate": "2027-06-01",
"status": "active",
"fileUrl": "https://files.nexspace365.com/creds/7.pdf"
}{
"error": {
"message": "Invalid or revoked API key",
"code": "UNAUTHENTICATED",
"suggestion": "Send a valid `Authorization: Bearer <token>` (nex_live_/nex_pat_ key, JWT, or OAuth access token).",
"retryable": false
}
}{
"error": {
"message": "<string>",
"code": "<string>",
"details": {},
"suggestion": "<string>",
"retryable": true
},
"requestId": "<string>"
}{
"error": {
"message": "<string>",
"code": "<string>",
"details": {},
"suggestion": "<string>",
"retryable": true
},
"requestId": "<string>"
}{
"error": {
"message": "Rate limit exceeded for this API key",
"code": "API_KEY_RATE_LIMITED",
"suggestion": "Wait until X-RateLimit-Reset before retrying, or batch operations.",
"retryable": true
}
}Authorizations
JWT token authentication
Headers
Pin the request to a dated API version (e.g. 2026-05-10). Applied by app-level middleware to every /api route (server/routes/index.ts → apiVersionMiddleware), which echoes the resolved value back in the NexSpace-Version response header. Omit to get the latest version. Discover the catalog at GET /.well-known/api-versions.
^\d{4}-\d{2}-\d{2}$Replay guard for write requests. Applied by app-level middleware to every /api route (server/routes/index.ts → idempotencyMiddleware), which only acts on POST/PUT/PATCH — GET, DELETE and OPTIONS ignore the header. Re-sending the same key with an identical body within 24 hours replays the original response; the same key with a different body returns 409.
255Path Parameters
Credential ID
Body
Response
The stored credential
Unique credential identifier
ID of the user the credential belongs to
Credential type (e.g., license, certification, training)
Human-readable credential name
Issuing authority or organization
Date the credential was issued
Date the credential expires
Current verification/validity status
active, expiring, expired, pending, rejected URL to the uploaded credential document

