> ## Documentation Index
> Fetch the complete documentation index at: https://private-7c7dfe99-parallel-read-in-order-multi-part.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Update reverse private endpoint

> Update mutable fields for an existing reverse private endpoint. customPrivateDnsMappings is a full replacement list. Use an empty array to clear mappings.

Update mutable fields for an existing reverse private endpoint. customPrivateDnsMappings is a full replacement list. Use an empty array to clear mappings.

<div data-permissions class="api-section">
  <div class="api-section-heading flex flex-col gap-y-4 w-full">
    <div class="flex items-baseline border-b pb-2.5 border-gray-100 dark:border-gray-800 w-full">
      <h4 class="api-section-heading-title flex-1 mb-0">Permission</h4>
    </div>
  </div>

  <div class="py-6">
    The API key must have the `control-plane:service:manage-clickpipes` permission.
  </div>
</div>


## OpenAPI

````yaml /_specs/cloud-openapi.json patch /v1/organizations/{organizationId}/services/{serviceId}/clickpipesReversePrivateEndpoints/{reversePrivateEndpointId}
openapi: 3.1.1
info:
  title: OpenAPI spec for ClickHouse Cloud
  version: '1.0'
  contact:
    name: ClickHouse Support
    url: >-
      https://clickhouse.com/docs/en/cloud/manage/openapi?referrer=openapi-1222280
    email: support@clickhouse.com
servers:
  - url: https://api.clickhouse.cloud
security:
  - basicAuth: []
tags:
  - name: Organization
  - name: Notifications
  - name: User management
  - name: Billing
  - name: Role Management
  - name: Service
  - name: Backup
  - name: Snapshot
  - name: API keys
  - name: Prometheus
  - name: ClickPipes
  - name: ClickStack
  - name: Postgres
  - name: UDF
  - name: Query API endpoints
  - name: Saved queries
paths:
  /v1/organizations/{organizationId}/services/{serviceId}/clickpipesReversePrivateEndpoints/{reversePrivateEndpointId}:
    patch:
      tags:
        - ClickPipes
      summary: Update reverse private endpoint
      description: >-
        Update mutable fields for an existing reverse private endpoint.
        customPrivateDnsMappings is a full replacement list. Use an empty array
        to clear mappings.
      operationId: clickPipeReversePrivateEndpointUpdate
      parameters:
        - in: path
          name: organizationId
          description: ID of the organization that owns the service.
          required: true
          schema:
            type: string
            format: uuid
        - in: path
          name: serviceId
          description: ID of the service that owns the Reverse Private Endpoint.
          required: true
          schema:
            type: string
            format: uuid
        - in: path
          name: reversePrivateEndpointId
          description: ID of the reverse private endpoint to update.
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateReversePrivateEndpoint'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 200
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
                  result:
                    $ref: '#/components/schemas/ReversePrivateEndpoint'
        '400':
          description: >-
            The request cannot be processed due to a client error. Please verify
            your request parameters and try again.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: number
                    description: HTTP status code.
                    example: 400
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
        '500':
          description: >-
            An internal server error has occurred. If this issue persists,
            please contact ClickHouse Cloud support for assistance.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: integer
                    description: HTTP status code.
                    example: 500
                  error:
                    type: string
                    description: Detailed error description.
                  requestId:
                    type: string
                    description: Unique id assigned to every request. UUIDv4
                    format: uuid
components:
  schemas:
    UpdateReversePrivateEndpoint:
      properties:
        customPrivateDnsMappings:
          type: array
          description: >-
            Optional private DNS names for Reverse Private Endpoint. Can be used
            as data source destination address. Must be unique across the
            ClickHouse service.

            Generally available for Google Private Service Connect (PSC). For
            AWS PrivateLink (VPC endpoint service and VPC resource), available
            in Private Preview; contact ClickHouse support to enable it for your
            service. Not supported for MSK multi-VPC.

            Supports exact names and leading wildcard names such as
            *.example.com
          items:
            $ref: '#/components/schemas/CustomPrivateDnsMapping'
          example:
            - privateDnsName: my-service.example.com
            - privateDnsName: '*.example.com'
    ReversePrivateEndpoint:
      properties:
        description:
          description: >-
            Reverse private endpoint description. Maximum length is 255
            characters.
          type: string
          example: My reverse private endpoint
        type:
          description: Reverse private endpoint type.
          type: string
          enum:
            - VPC_ENDPOINT_SERVICE
            - VPC_RESOURCE
            - MSK_MULTI_VPC
            - GCP_PSC_SERVICE_ATTACHMENT
          example: VPC_ENDPOINT_SERVICE
        vpcEndpointServiceName:
          description: VPC endpoint service name.
          type:
            - string
            - 'null'
          example: com.amazonaws.vpce.us-east-1.vpce-svc-12345678901234567
        vpcResourceConfigurationId:
          description: VPC resource configuration ID. Required for VPC_RESOURCE type.
          type:
            - string
            - 'null'
          example: rcfg-12345678901234567
        vpcResourceShareArn:
          description: VPC resource share ARN. Required for VPC_RESOURCE type.
          type:
            - string
            - 'null'
          example: >-
            arn:aws:ram:us-east-1:123456789012:resource-share/share-12345678901234567
        mskClusterArn:
          description: MSK cluster ARN. Required for MSK_MULTI_VPC type.
          type:
            - string
            - 'null'
          example: >-
            arn:aws:kafka:us-east-1:123456789012:cluster/my-cluster/a1b2c3d4-5678-90ab-cdef-1234567890ab-1
        mskAuthentication:
          description: MSK cluster authentication type. Required for MSK_MULTI_VPC type.
          type:
            - string
            - 'null'
          enum:
            - SASL_IAM
            - SASL_SCRAM
          example: SASL_IAM
        gcpServiceAttachment:
          description: >-
            Private Preview. GCP PSC service attachment URI. Required for
            GCP_PSC_SERVICE_ATTACHMENT type. Format:
            projects/{project}/regions/{region}/serviceAttachments/{name}.
          type:
            - string
            - 'null'
          example: >-
            projects/my-project/regions/us-central1/serviceAttachments/my-service
        customPrivateDnsMappings:
          type: array
          description: >-
            Optional private DNS names for Reverse Private Endpoint. Can be used
            as data source destination address. Must be unique across the
            ClickHouse service.

            Generally available for Google Private Service Connect (PSC). For
            AWS PrivateLink (VPC endpoint service and VPC resource), available
            in Private Preview; contact ClickHouse support to enable it for your
            service. Not supported for MSK multi-VPC.

            Supports exact names and leading wildcard names such as
            *.example.com
          items:
            $ref: '#/components/schemas/CustomPrivateDnsMapping'
          example:
            - privateDnsName: my-service.example.com
            - privateDnsName: '*.example.com'
        id:
          description: Reverse private endpoint ID.
          type: string
          format: uuid
          example: 12345678-1234-1234-1234-123456789012
        serviceId:
          description: ClickHouse service ID reverse private endpoint is associated with.
          type: string
          format: uuid
          example: 12345678-1234-1234-1234-123456789012
        endpointId:
          description: Reverse private endpoint endpoint ID.
          type: string
          example: vpce-12345678901234567
        dnsNames:
          type: array
          description: Reverse private endpoint internal DNS names.
          items:
            type: string
          example:
            - >-
              vpce-12345678901234567-abcdefg.execute-api.us-east-1.vpce.amazonaws.com
        privateDnsNames:
          type: array
          description: Reverse private endpoint private DNS names.
          items:
            type: string
          example:
            - >-
              vpce-12345678901234567-abcdefg.execute-api.us-east-1.vpce.amazonaws.com
        privateDnsMappings:
          type: array
          description: >-
            Read-only provider private DNS names and their internal DNS targets
            reported by the Reverse Private Endpoint. For VPC_RESOURCE, this
            list can be empty when CHILD resources have no provider private DNS.
          items:
            $ref: '#/components/schemas/ReversePrivateEndpointPrivateDnsMapping'
          example:
            - privateDnsName: my-service.example.com
              internalDnsName: internal.example.com
        dnsTargets:
          type: array
          description: >-
            Read-only DNS targets the Reverse Private Endpoint currently
            reports. For VPC_RESOURCE, there is one RESOURCE_CONFIGURATION
            target per resource configuration association, identified by its
            CHILD resource configuration ID, or the configuration ID for a
            single resource. Other endpoint types report an empty list. Targets
            can appear over time; a custom mapping with a targetId that is not
            reported yet is not served until it appears.
          items:
            $ref: '#/components/schemas/ReversePrivateEndpointDnsTarget'
          example:
            - id: rcfg-097648d8068504966
              kind: RESOURCE_CONFIGURATION
              internalDnsName: internal.example.com
        status:
          description: Reverse private endpoint status.
          type: string
          enum:
            - Unknown
            - Provisioning
            - Deleting
            - Ready
            - Failed
            - PendingAcceptance
            - Rejected
            - Expired
          example: Ready
    CustomPrivateDnsMapping:
      properties:
        privateDnsName:
          description: >-
            Optional private DNS names for Reverse Private Endpoint. Can be used
            as data source destination address. Must be unique across the
            ClickHouse service.

            Generally available for Google Private Service Connect (PSC). For
            AWS PrivateLink (VPC endpoint service and VPC resource), available
            in Private Preview; contact ClickHouse support to enable it for your
            service. Not supported for MSK multi-VPC.

            Supports exact names and leading wildcard names such as
            *.example.com
          type: string
          example: '*.my-service.example.com'
        targetId:
          description: >-
            Optional DNS target ID. Supported only for VPC_RESOURCE, where it is
            the CHILD resource configuration ID (rcfg-…), or the configuration
            ID for a single resource. Set it at create time to route a custom
            DNS name to that resource. If the target is not reported in
            dnsTargets yet, the mapping is not served until it appears; it does
            not fall back to the default target. If omitted, the default target
            is used. Once dnsTargets is non-empty, adding or changing a targetId
            requires an ID in that list; unchanged target IDs are not
            re-checked.
          type: string
          example: rcfg-097648d8068504966
    ReversePrivateEndpointPrivateDnsMapping:
      properties:
        privateDnsName:
          description: Provider private DNS name reported by the Reverse Private Endpoint.
          type: string
          example: my-service.example.com
        internalDnsName:
          description: Internal DNS target for the provider private DNS name.
          type: string
          example: >-
            vpce-0123456789abcdef0-abcdefg.vpce-svc-0123456789abcdef0.us-east-1.vpce.amazonaws.com
    ReversePrivateEndpointDnsTarget:
      properties:
        id:
          description: >-
            DNS target ID. For VPC_RESOURCE, the associated CHILD resource
            configuration ID, or the configuration ID for a single resource.
          type: string
          example: rcfg-097648d8068504966
        kind:
          description: DNS target kind.
          type: string
          enum:
            - RESOURCE_CONFIGURATION
          example: RESOURCE_CONFIGURATION
        internalDnsName:
          description: >-
            Internal DNS name currently reported for this target. To select a
            target for a custom private DNS mapping, use its id as targetId.
          type: string
          example: >-
            vpce-052ef252671124ada.rcfg-097648d8068504966.4232ccc.vpc-lattice-rsc.us-east-1.on.aws
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: >-
        Use key ID and key secret obtained in ClickHouse Cloud console:
        https://clickhouse.com/docs/cloud/manage/openapi
      x-permission-scopes: >-
        The scope list of a `security` requirement holds ClickHouse Cloud API
        key permission ids (for example `control-plane:organization:view`), not
        OAuth scopes. OpenAPI has no field for API key permissions, so this is
        the closest available place. A key must hold every permission listed on
        an operation to call it; an operation with no scopes needs none beyond a
        valid key. Every operation declares at most one requirement object,
        always for this scheme, so the list is only ever conjunctive —
        alternative sets of permissions are never expressed.

````