Create a credential

POST/credentials

Issues a new API credential for the current account and, optionally, its initial access policies.

Each entry in policies specifies either a list of capabilities or a policy template, together with the resources it applies to. Available templates are returned by the list policy templates operation.

The credential secret is returned only in this response and cannot be retrieved again. Store it securely. Retrying the request with the same Idempotency-Key does not return the secret again; it returns 409 with the secret_not_replayable error code.

The new credential cannot receive permissions beyond those the calling credential is allowed to delegate. Such requests are rejected with delegation_limit_exceeded and no credential is issued.

AuthorizationBearer <token>

Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.

In: header

Header Parameters

Idempotency-Key*string

Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Required by this operation: a missing key returns idempotency_key_required, and a malformed key returns idempotency_key_invalid. Repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.

X-Client-Request-Id?string

Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.

Lengthlength <= 64

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/credentials" \  -H "Idempotency-Key: string" \  -H "Content-Type: application/json" \  -d '{    "name": "string"  }'
{  "data": {    "auth_mode": "autonomous",    "created_at": "2019-08-24T14:15:22Z",    "created_by": {      "id": "string",      "kind": "admin"    },    "environment": "production",    "expires_at": "2019-08-24T14:15:22Z",    "human": {      "admin_id": "string",      "eligible_since": "2019-08-24T14:15:22Z",      "expires_at": "2019-08-24T14:15:22Z"    },    "id": "string",    "name": "string",    "object": "credential",    "policy": {      "active_version": 0,      "auth_revision": 0    },    "purpose": "string",    "revision": 0,    "revoked_at": "2019-08-24T14:15:22Z",    "revoked_by": {      "id": "string",      "kind": "admin"    },    "secret": {      "configured": true,      "issued_at": "2019-08-24T14:15:22Z",      "last4": "string",      "rotated_at": "2019-08-24T14:15:22Z",      "valid_until": "2019-08-24T14:15:22Z",      "value": "string",      "version": 0    },    "status": "active",    "updated_at": "2019-08-24T14:15:22Z"  }}