List credentials
/credentialsReturns all credentials of the current account, including the calling credential. Requires the credentials.read permission; resource-level restrictions do not apply to this collection.
Results are paginated with a cursor and can be filtered by status and sorted by creation date.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Query Parameters
Maximum number of items to return, from 1 to 200.
1 <= value <= 200Cursor for the next page, taken from page.next_cursor of the previous response.
Sort order. A leading - sorts in descending order.
Value in
- "created_at"
- "-created_at"
Only credentials with this status.
Value in
- "active"
- "suspended"
- "revoked"
Header Parameters
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/credentials"{ "data": [ { "auth_mode": "autonomous", "created_at": "2019-08-24T14:15:22Z", "created_by": { "id": "string", "kind": "admin" }, "environment": "production", "expires_at": "2019-08-24T14:15:22Z", "human": { "admin_id": "string", "eligible_since": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z" }, "id": "string", "name": "string", "object": "credential", "policy": { "active_version": 0, "auth_revision": 0 }, "purpose": "string", "revision": 0, "revoked_at": "2019-08-24T14:15:22Z", "revoked_by": { "id": "string", "kind": "admin" }, "secret": { "configured": true, "issued_at": "2019-08-24T14:15:22Z", "last4": "string", "rotated_at": "2019-08-24T14:15:22Z", "valid_until": "2019-08-24T14:15:22Z", "value": "string", "version": 0 }, "status": "active", "updated_at": "2019-08-24T14:15:22Z" } ], "page": { "limit": 1, "next_cursor": "string", "prev_cursor": "string" }}Credentials15
Credentials in API v3: list credentials, create a credential, retrieve the current credential, retrieve the current credential's policies, retrieve the permission catalog, list policy templates, retrieve a credential, update a credential, delete a credential, list credential policies, add a credential policy, retrieve a credential policy, update a credential policy, remove a credential policy, rotate a credential secret.
Create a credential POST
Issues a new API credential for the current account and, optionally, its initial access policies. Each entry in `policies` specifies either a list of `capabilities` or a policy `template`, together with the `resources` it applies to. Available templates are returned by the list policy templates operation. The credential secret is returned only in this response and cannot be retrieved again. Store it securely. Retrying the request with the same `Idempotency-Key` does not return the secret again; it returns `409` with the `secret_not_replayable` error code. The new credential cannot receive permissions beyond those the calling credential is allowed to delegate. Such requests are rejected with `delegation_limit_exceeded` and no credential is issued.