Create Credential
api/beta/vaults/credentials/create
History
api/beta/vaults/credentials/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/vaults/credentials/create Changed · +67 / -68 lines
# Create Credential ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200) ## Create Credential ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
---- -title: Create Credential -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/create ---- +# Create Credential -## Create Credential +**POST** `/v1/vaults/{vault_id}/credentials` -**post** `/v1/vaults/{vault_id}/credentials` - Create Credential -### Path Parameters +## Path parameters - `vault_id: string` -### Header Parameters +## Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +## Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams` Authentication details for creating a credential. - - `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` + - `BetaManagedAgentsMCPOAuthCreateParams object` Parameters for creating an MCP OAuth credential.
OAuth access token. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `client_secret: string`
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` - Token endpoint uses POST body authentication with client credentials. - `client_secret: string`
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` + minLength: 1, maxLength: 8192 + - `BetaManagedAgentsStaticBearerCreateParams object` + Parameters for creating a static bearer token credential. - `token: string`
Static bearer token value. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableCreateParams object` - - `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` - Parameters for creating an environment variable credential. - `networking: BetaManagedAgentsCredentialNetworkingParams`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - Substitute the secret only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. Immutable after create. + minLength: 1, maxLength: 255 + - `secret_value: string` Secret value. Write-only; never returned in responses. + minLength: 1, maxLength: 4096 + - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` Where in the outbound request the secret value may be substituted.
Human-readable name for the credential. Up to 255 characters. + maxLength: 255 + - `metadata: optional map[string]` Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars. -### Returns +## Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - Environment variable credential details. The secret value is never returned. - `injection_location: BetaManagedAgentsInjectionLocationResponse`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - The secret is substituted only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable.
- `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +### Response (200) ```json {
api/beta/vaults/credentials/create Changed · +3 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 30 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` - `"message-batches-2024-09-24"`
- `"output-300k-2026-03-24"` - `"user-profiles-2026-03-24"` + + - `"user-profiles-2026-08-18"` - `"advisor-tool-2026-03-01"`
api/beta/vaults/credentials/create First recorded · 460 lines, first recorded
## Create Credential ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
The first capture of this source. The page was already there, and this is what it said.
---
title: Create Credential
url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/create
---
## Create Credential
**post** `/v1/vaults/{vault_id}/credentials`
Create Credential
### Path Parameters
- `vault_id: string`
### Header Parameters
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 30 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
### Body Parameters
- `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams`
Authentication details for creating a credential.
- `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }`
Parameters for creating an MCP OAuth credential.
- `access_token: string`
OAuth access token.
- `mcp_server_url: string`
URL of the MCP server this credential authenticates against.
- `type: "mcp_oauth"`
- `"mcp_oauth"`
- `expires_at: optional string or null`
A timestamp in RFC 3339 format
- `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null`
OAuth refresh token parameters for creating a credential with refresh support.
- `client_id: string`
OAuth client ID.
- `refresh_token: string`
OAuth refresh token.
- `token_endpoint: string`
Token endpoint URL used to refresh the access token.
- `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam`
Token endpoint requires no client authentication.
- `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }`
Token endpoint requires no client authentication.
- `type: "none"`
- `"none"`
- `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }`
Token endpoint uses HTTP Basic authentication with client credentials.
- `client_secret: string`
OAuth client secret.
- `type: "client_secret_basic"`
- `"client_secret_basic"`
- `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }`
Token endpoint uses POST body authentication with client credentials.
- `client_secret: string`
OAuth client secret.
- `type: "client_secret_post"`
- `"client_secret_post"`
- `resource: optional string or null`
OAuth resource indicator.
- `scope: optional string or null`
OAuth scope for the refresh request.
- `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }`
Parameters for creating a static bearer token credential.
- `token: string`
Static bearer token value.
- `mcp_server_url: string`
URL of the MCP server this credential authenticates against.
- `type: "static_bearer"`
- `"static_bearer"`
- `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }`
Parameters for creating an environment variable credential.
- `networking: BetaManagedAgentsCredentialNetworkingParams`
Outbound hosts the secret value is substituted on.
- `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }`
Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.
- `type: "unrestricted"`
- `"unrestricted"`
- `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }`
Substitute the secret only on requests to the listed hosts.
- `allowed_hosts: array of string`
Hostnames on which the secret will be substituted. Each entry is a bare hostname (`api.example.com`), an IPv4 address (`192.0.2.1`), or a `*.`-prefixed wildcard (`*.example.com`). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.
- `type: "limited"`
- `"limited"`
- `secret_name: string`
Name of the environment variable. Immutable after create.
- `secret_value: string`
Secret value. Write-only; never returned in responses.
- `type: "environment_variable"`
- `"environment_variable"`
- `injection_location: optional BetaManagedAgentsInjectionLocationParams`
Where in the outbound request the secret value may be substituted.
- `body: optional boolean`
Substitute when the placeholder appears in the request body.
- `header: optional boolean`
Substitute when the placeholder appears in a request header value.
- `display_name: optional string or null`
Human-readable name for the credential. Up to 255 characters.
- `metadata: optional map[string]`
Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars.
### Returns
- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }`
A credential stored in a vault. Sensitive fields are never returned in responses.
- `id: string`
Unique identifier for the credential.
- `archived_at: string or null`
A timestamp in RFC 3339 format
- `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse`
Authentication details for a credential.
- `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }`
OAuth credential details for an MCP server.
- `mcp_server_url: string`
URL of the MCP server this credential authenticates against.
- `type: "mcp_oauth"`
- `"mcp_oauth"`
- `expires_at: optional string or null`
A timestamp in RFC 3339 format
- `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null`
OAuth refresh token configuration returned in credential responses.
- `client_id: string`
OAuth client ID.
- `token_endpoint: string`
Token endpoint URL used to refresh the access token.
- `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse`
Cut at 300 lines.