Delete a credential
/credentials/{credential_id}Deletes a revoked or expired credential. After deletion, the credential is no longer returned by the API, while audit records that reference it are preserved.
Credentials that are still valid cannot be deleted and return the state_conflict error code. Revoke the credential with the update operation first.
A credential cannot delete itself.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Response Body
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/credentials/string"Update a credential PATCH
Updates the `name`, `purpose`, or `expires_at` of a credential, or changes its `status`. Setting `status` to `suspended` suspends the credential, and setting it to `active` reactivates it. `inactive` is a deprecated alias of `suspended`. Setting `status` to `revoked` permanently revokes the credential; revocation cannot be undone. Send the `ETag` returned by the retrieve operation in the `If-Match` header to avoid overwriting a newer version. A credential cannot update itself.
List credential policies GET
Returns the policies in the credential's active policy revision, one item per policy. A credential without policies returns an empty collection.