Retrieve a credential
/credentials/{credential_id}Retrieves a credential by its public ID.
The secret object exposes only metadata, such as the last four characters and the rotation date. The secret value itself is never returned by this operation.
The response includes an ETag representing the current revision. Send this value in the If-Match header when updating the credential to avoid overwriting a newer version.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Response Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/credentials/string"{ "data": { "auth_mode": "autonomous", "created_at": "2019-08-24T14:15:22Z", "created_by": { "id": "string", "kind": "admin" }, "environment": "production", "expires_at": "2019-08-24T14:15:22Z", "human": { "admin_id": "string", "eligible_since": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z" }, "id": "string", "name": "string", "object": "credential", "policy": { "active_version": 0, "auth_revision": 0 }, "purpose": "string", "revision": 0, "revoked_at": "2019-08-24T14:15:22Z", "revoked_by": { "id": "string", "kind": "admin" }, "secret": { "configured": true, "issued_at": "2019-08-24T14:15:22Z", "last4": "string", "rotated_at": "2019-08-24T14:15:22Z", "valid_until": "2019-08-24T14:15:22Z", "value": "string", "version": 0 }, "status": "active", "updated_at": "2019-08-24T14:15:22Z" }}List policy templates GET
Returns the predefined policy templates that can be used when creating a credential, each with the list of permissions it grants. No template includes `administrators.*` or `credentials.*` permissions. Available to any authenticated credential. Reading the templates does not grant any permission.
Update a credential PATCH
Updates the `name`, `purpose`, or `expires_at` of a credential, or changes its `status`. Setting `status` to `suspended` suspends the credential, and setting it to `active` reactivates it. `inactive` is a deprecated alias of `suspended`. Setting `status` to `revoked` permanently revokes the credential; revocation cannot be undone. Send the `ETag` returned by the retrieve operation in the `If-Match` header to avoid overwriting a newer version. A credential cannot update itself.