Get Credential
api/beta/vaults/credentials/retrieve
History
api/beta/vaults/credentials/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/retrieve Changed · +28 / -43 lines
# Get Credential ## Path parameters ## Headers ## Returns ## Example ### Response (200) ## Get Credential ### Path Parameters ### Header Parameters ### Returns ### Example #### Response
---- -title: Get Credential -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/retrieve ---- +# Get Credential -## Get Credential +**GET** `/v1/vaults/{vault_id}/credentials/{credential_id}` -**get** `/v1/vaults/{vault_id}/credentials/{credential_id}` - Get Credential -### Path Parameters +## Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +## Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +## Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - Environment variable credential details. The secret value is never returned. - `injection_location: BetaManagedAgentsInjectionLocationResponse`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - The secret is substituted only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable.
- `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +### Response (200) ```json {
api/beta/vaults/credentials/retrieve Changed · +3 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 30 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` - `"message-batches-2024-09-24"`
- `"output-300k-2026-03-24"` - `"user-profiles-2026-03-24"` + + - `"user-profiles-2026-08-18"` - `"advisor-tool-2026-03-01"`
api/beta/vaults/credentials/retrieve First recorded · 288 lines, first recorded
## Get Credential ### Path Parameters ### Header Parameters ### Returns ### Example #### Response
The first capture of this source. The page was already there, and this is what it said.
---
title: Get Credential
url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/retrieve
---
## Get Credential
**get** `/v1/vaults/{vault_id}/credentials/{credential_id}`
Get Credential
### Path Parameters
- `vault_id: string`
- `credential_id: string`
### Header Parameters
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 30 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
### Returns
- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }`
A credential stored in a vault. Sensitive fields are never returned in responses.
- `id: string`
Unique identifier for the credential.
- `archived_at: string or null`
A timestamp in RFC 3339 format
- `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse`
Authentication details for a credential.
- `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }`
OAuth credential details for an MCP server.
- `mcp_server_url: string`
URL of the MCP server this credential authenticates against.
- `type: "mcp_oauth"`
- `"mcp_oauth"`
- `expires_at: optional string or null`
A timestamp in RFC 3339 format
- `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null`
OAuth refresh token configuration returned in credential responses.
- `client_id: string`
OAuth client ID.
- `token_endpoint: string`
Token endpoint URL used to refresh the access token.
- `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse`
Token endpoint requires no client authentication.
- `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }`
Token endpoint requires no client authentication.
- `type: "none"`
- `"none"`
- `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }`
Token endpoint uses HTTP Basic authentication with client credentials.
- `type: "client_secret_basic"`
- `"client_secret_basic"`
- `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }`
Token endpoint uses POST body authentication with client credentials.
- `type: "client_secret_post"`
- `"client_secret_post"`
- `resource: optional string or null`
OAuth resource indicator.
- `scope: optional string or null`
OAuth scope for the refresh request.
- `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }`
Static bearer token credential details for an MCP server.
- `mcp_server_url: string`
URL of the MCP server this credential authenticates against.
- `type: "static_bearer"`
- `"static_bearer"`
- `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }`
Environment variable credential details. The secret value is never returned.
- `injection_location: BetaManagedAgentsInjectionLocationResponse`
Where in the outbound request the secret value is substituted.
- `body: boolean`
Whether the placeholder is substituted in the request body.
- `header: boolean`
Whether the placeholder is substituted in request header values.
- `networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse`
Outbound hosts the secret value is substituted on.
- `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }`
The secret is substituted on any host the session's Environment network policy permits egress to.
- `type: "unrestricted"`
- `"unrestricted"`
- `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }`
The secret is substituted only on requests to the listed hosts.
- `allowed_hosts: array of string`
Hostnames on which the secret will be substituted. An entry matches the request host exactly; a `*.`-prefixed entry matches any subdomain of the named domain but not the domain itself.
- `type: "limited"`
- `"limited"`
- `secret_name: string`
Name of the environment variable.
- `type: "environment_variable"`
- `"environment_variable"`
- `created_at: string`
A timestamp in RFC 3339 format
- `metadata: map[string]`
Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"`
- `"vault_credential"`
- `updated_at: string`
A timestamp in RFC 3339 format
- `vault_id: string`
Identifier of the vault this credential belongs to.
- `display_name: optional string or null`
Human-readable name for the credential.
### Example
```http
curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \
-H 'anthropic-version: 2023-06-01' \
-H 'anthropic-beta: managed-agents-2026-04-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response
```json
{
"id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
"archived_at": null,
"auth": {
"mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
"type": "static_bearer"
},
"created_at": "2026-03-15T10:00:00Z",
"metadata": {
"environment": "production"
},
"type": "vault_credential",
"updated_at": "2026-03-15T10:00:00Z",
"vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
"display_name": "Example credential"
}
```