Create a credential
Requires the global credential.add permission.
curl --request POST \
--url https://custos.example.com/credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "<string>",
"username": "<string>",
"password": "<string>",
"notes": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"requires_permission": true
}
'import requests
url = "https://custos.example.com/credentials"
payload = {
"label": "<string>",
"username": "<string>",
"password": "<string>",
"notes": "<string>",
"metadata": {},
"tags": ["<string>"],
"requires_permission": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
label: '<string>',
username: '<string>',
password: '<string>',
notes: '<string>',
metadata: {},
tags: ['<string>'],
requires_permission: true
})
};
fetch('https://custos.example.com/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://custos.example.com/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => '<string>',
'username' => '<string>',
'password' => '<string>',
'notes' => '<string>',
'metadata' => [
],
'tags' => [
'<string>'
],
'requires_permission' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://custos.example.com/credentials"
payload := strings.NewReader("{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://custos.example.com/credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://custos.example.com/credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"username": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"created_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"updated_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"permissions": [
"<string>"
],
"requires_permission": true,
"access_status": "not_required",
"access_expires_at": "2023-11-07T05:31:56Z"
}Authorizations
An opaque access token from /login or /refresh. Tokens are checked against the database on every request, so revocation is immediate.
Body
Arbitrary string map, returned by list and get without any reveal. Never put secret values here — use password or notes.
Show child attributes
Show child attributes
When true, holding credential.read is not enough to reveal the value — the caller also needs an approved, unexpired permission request.
Response
Credential created
Visible in list responses without a reveal, so it must not hold secrets.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The caller's permissions on this credential.
Whether revealing the value needs an approved permission request.
not_required when the credential is ungated. Otherwise the caller's standing: approved (admins, or an unexpired approval), pending, or requestable.
not_required, approved, pending, requestable When an approved access window ends. Absent for admins and ungated credentials.
curl --request POST \
--url https://custos.example.com/credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "<string>",
"username": "<string>",
"password": "<string>",
"notes": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"requires_permission": true
}
'import requests
url = "https://custos.example.com/credentials"
payload = {
"label": "<string>",
"username": "<string>",
"password": "<string>",
"notes": "<string>",
"metadata": {},
"tags": ["<string>"],
"requires_permission": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
label: '<string>',
username: '<string>',
password: '<string>',
notes: '<string>',
metadata: {},
tags: ['<string>'],
requires_permission: true
})
};
fetch('https://custos.example.com/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://custos.example.com/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => '<string>',
'username' => '<string>',
'password' => '<string>',
'notes' => '<string>',
'metadata' => [
],
'tags' => [
'<string>'
],
'requires_permission' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://custos.example.com/credentials"
payload := strings.NewReader("{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://custos.example.com/credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://custos.example.com/credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"<string>\",\n \"username\": \"<string>\",\n \"password\": \"<string>\",\n \"notes\": \"<string>\",\n \"metadata\": {},\n \"tags\": [\n \"<string>\"\n ],\n \"requires_permission\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"username": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"created_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"updated_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"permissions": [
"<string>"
],
"requires_permission": true,
"access_status": "not_required",
"access_expires_at": "2023-11-07T05:31:56Z"
}