Credentials
Credentials store the connection details your tasks use to reach third-party systems such as Jira, Slack or AWS. Create, test and share them, and attach them to projects.
List credentials
Lists one page of the credentials the caller can see, newest first, with a `total` for paging by `page` and `per`. Filters by `type`, name search `q`, `mine`, `created_by_id`, `org_id` and whether secrets are stored (`secrets`). Never returns secret values.
Create credential
Creates a credential from a type, name, description and config; secret fields may arrive sealed with the seal key, which then requires a client-chosen `id` (409 when that id was ever used). The credential is personal unless `ownership` makes it the organization's, which requires the Org Owner or Org Admin role. Returns 201 with the credential, without secret values.
Start credential connect
Starts the OAuth2 Connect flow for a saved credential and returns the provider's consent URL. Returns 400 until the credential stores its client ID, secret and the provider endpoints its type needs; in tenant organizations a type whose endpoints the credential supplies itself returns 403. Requires edit access to the credential.
Move credential folder
Moves a credential folder (a `/`-separated name prefix) under `destination`, renaming every credential beneath it in one all-or-nothing change. `ids` must list exactly the credentials the caller sees in the folder, or it returns 409. Returns the count moved.
Cancel credential OAuth
Abandons the caller's in-progress OAuth wizard named by `flow_id`. Always returns 204, including when no such wizard exists.
Complete credential OAuth
Finishes an OAuth wizard by submitting the pasted authorization `code` and storing the result as a credential. Returns 201 with a new credential, or 200 when `credential_id` names an existing one to update. Never returns secret values.
Start credential OAuth
Starts an OAuth wizard for a credential type and returns the provider's consent URL plus a `flow_id` to complete or cancel it. Starting one ends the caller's previous wizard. Not available in tenant organizations (403).
List credential orgs
Lists the organizations owning credentials the caller can see, each with its credential count, including a no-organization entry with a null `id` that `org_id=none` selects.
List credential owners
Lists the people who created credentials the caller can see, each with a credential count, highest count first. Each `id` is a value for the list's `created_by_id` filter.
Get credential seal key
Returns the public key (base64 SPKI DER), algorithm and key id that seal secret field values in the client before they are sent. Returns 503 when the key is unavailable.
Test credential
Tests a connection from a `type` and `config`, filling blank secrets from the saved credential named by `id`. A completed test returns 200 with its outcome, whether it passed or failed. Not available in tenant organizations (403).
List credential types
Lists the credential types in display order, each with its fields, whether it can be tested and which OAuth flows it offers. Forms render their fields from this list.
Delete credential
Deletes a credential and retires its id so it is never reused. Requires delete access to the credential. Returns 204 with no body.
Get credential
Returns one credential the caller can see, with its non-secret config, the names of its stored secrets in `secrets_set` and whether the caller may edit it. Never returns secret values.
Update credential
Updates a credential's name, description, type or config; omitted fields and config keys keep their stored values, so secrets need not be resent unless `type` changes, which starts the config empty. Sending `id` or `ownership`, or changing the destination URL while keeping a stored secret, returns 400. Requires edit access to the credential; returns the credential.
Get credential access
Returns who may use a credential: its owner when personal, whether it is a system credential, and the projects it is attached to that the caller can see. Never includes config.
Attach project credential
Attaches a credential to a project so work in that project can use it. Requires edit access to the project; the credential's owner may attach it, and an Org Owner or Org Admin may attach any organization credential but not someone else's personal one. A system credential or an agent account's own key returns 422; otherwise returns 201 when attached and 200 when already attached.
Detach project credential
Detaches a credential from a project. Requires edit access to the project, plus ownership of the credential or the Org Owner or Org Admin role. Returns 404 when it is not attached there, 204 with no body otherwise.