# Update

Launch stage: GA

`PATCH /api/2.0/accounts/{account_id}/oauth2/custom-app-integrations/{integration_id}`

Updates an existing custom OAuth App Integration.
 You can retrieve the custom OAuth app integration via [CustomAppIntegration/get](https://docs.databricks.com/api/account/customappintegration/get).

API scopes: authentication

## Path parameters

- `account_id` (string, optional)
- `integration_id` (string, optional)

## Request body

- `redirect_urls` (array of string, optional)
  List of OAuth redirect urls to be updated in the custom OAuth app integration
- `token_access_policy` (object, optional)
  Token access policy to be updated in the custom OAuth app integration
  - `access_token_ttl_in_minutes` (int32, optional)
    access token time to live in minutes
    Constraints: `[ 5 .. 1440 ]`
  - `refresh_token_ttl_in_minutes` (int32, optional)
    Refresh token time to live in minutes.
     When single-use refresh tokens are enabled, this represents the TTL of an individual refresh token.
     If the refresh token is used before it expires, a new one is issued with a renewed individual TTL.
    Constraints: `[ 5 .. 129600 ]`
  - `enable_single_use_refresh_tokens` (boolean, optional, Beta)
    Whether to enable single-use refresh tokens (refresh token rotation).
     If this feature is enabled, upon successfully getting a new access token using a refresh token, <Databricks> will
     issue a new refresh token along with the access token in the response and invalidate the old refresh token.
     The client should use the new refresh token to get access tokens in future requests.
  - `absolute_session_lifetime_in_minutes` (int32, optional, Beta)
    Absolute OAuth session TTL in minutes. Effective only when the single-use refresh token feature is enabled.
     This is the absolute TTL of all refresh tokens issued in one OAuth session. When a new refresh token is issued
     during refresh token rotation, it will inherit the same absolute TTL as the old refresh token.
     In other words, this represents the maximum amount of time a user can stay logged in without re-authenticating.
- `scopes` (array of string, optional)
  List of OAuth scopes to be updated in the custom OAuth app integration, similar to redirect URIs this will fully
   replace the existing values instead of appending
- `user_authorized_scopes` (array of string, optional)
  Scopes that will need to be consented by end user to mint the access token. If the user does
   not authorize the access token will not be minted.
   Must be a subset of scopes.

## Request

```json
{
  "token_access_policy": {
    "access_token_ttl_in_minutes": 120,
    "refresh_token_ttl_in_minutes": 200
  }
}
```

## Response

```json
{}
```

