Skip to main content
POST
Create a credential

Authorizations

Authorization
string
header
required

An opaque access token from /login or /refresh. Tokens are checked against the database on every request, so revocation is immediate.

Body

application/json
label
string
required
username
string
password
string
notes
string
metadata
object

Arbitrary string map, returned by list and get without any reveal. Never put secret values here — use password or notes.

tags
string[]
requires_permission
boolean

When true, holding credential.read is not enough to reveal the value — the caller also needs an approved, unexpired permission request.

Response

Credential created

id
string<uuid>
label
string
username
string
metadata
object

Visible in list responses without a reveal, so it must not hold secrets.

tags
string[]
created_by
object | null
updated_by
object | null
created_at
string<date-time>
updated_at
string<date-time>
permissions
string[]

The caller's permissions on this credential.

requires_permission
boolean

Whether revealing the value needs an approved permission request.

access_status
enum<string>

not_required when the credential is ungated. Otherwise the caller's standing: approved (admins, or an unexpired approval), pending, or requestable.

Available options:
not_required,
approved,
pending,
requestable
access_expires_at
string<date-time>

When an approved access window ends. Absent for admins and ungated credentials.