Reveal a credential value
Returns the decrypted password and notes, and writes an audit record. Requires credential.read, plus an approved unexpired permission request when the credential sets requires_permission.
curl --request GET \
--url https://custos.example.com/credentials/{id}/reveal \
--header 'Authorization: Bearer <token>'import requests
url = "https://custos.example.com/credentials/{id}/reveal"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://custos.example.com/credentials/{id}/reveal', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://custos.example.com/credentials/{id}/reveal",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://custos.example.com/credentials/{id}/reveal"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://custos.example.com/credentials/{id}/reveal")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://custos.example.com/credentials/{id}/reveal")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"username": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"created_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"updated_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"permissions": [
"<string>"
],
"requires_permission": true,
"access_status": "not_required",
"access_expires_at": "2023-11-07T05:31:56Z",
"password": "<string>",
"notes": "<string>"
}Authorizations
An opaque access token from /login or /refresh. Tokens are checked against the database on every request, so revocation is immediate.
Path Parameters
Response
The credential with its secret fields
Visible in list responses without a reveal, so it must not hold secrets.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The caller's permissions on this credential.
Whether revealing the value needs an approved permission request.
not_required when the credential is ungated. Otherwise the caller's standing: approved (admins, or an unexpired approval), pending, or requestable.
not_required, approved, pending, requestable When an approved access window ends. Absent for admins and ungated credentials.
curl --request GET \
--url https://custos.example.com/credentials/{id}/reveal \
--header 'Authorization: Bearer <token>'import requests
url = "https://custos.example.com/credentials/{id}/reveal"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://custos.example.com/credentials/{id}/reveal', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://custos.example.com/credentials/{id}/reveal",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://custos.example.com/credentials/{id}/reveal"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://custos.example.com/credentials/{id}/reveal")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://custos.example.com/credentials/{id}/reveal")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"username": "<string>",
"metadata": {},
"tags": [
"<string>"
],
"created_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"updated_by": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"display_name": "<string>",
"email": "jsmith@example.com"
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"permissions": [
"<string>"
],
"requires_permission": true,
"access_status": "not_required",
"access_expires_at": "2023-11-07T05:31:56Z",
"password": "<string>",
"notes": "<string>"
}