Vaults
api/beta/vaults
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/vaults Changed · +317 / -1466 lines
### Headers ### Body parameters #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## Vaults › Credentials ### Create Credential #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Credentials #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Credential #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Credential #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Delete Credential #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Archive Credential #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Validate Credential #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Header Parameters ### Body Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Credentials ## Create Credential ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## List Credentials ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Get Credential ### Path Parameters ### Header Parameters #### Response ## Update Credential ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Delete Credential ### Path Parameters ### Header Parameters #### Response ## Archive Credential ### Path Parameters ### Header Parameters #### Response ## Validate Credential ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Beta Managed Agents Credential ### Beta Managed Agents Credential Networking Params ### Beta Managed Agents Credential Validation ### Beta Managed Agents Credential Validation Status ### Beta Managed Agents Deleted Credential ### Beta Managed Agents Environment Variable Auth Response ### Beta Managed Agents Environment Variable Create Params ### Beta Managed Agents Environment Variable Update Params ### Beta Managed Agents Injection Location Params ### Beta Managed Agents Injection Location Response ### Beta Managed Agents Injection Location Update Params ### Beta Managed Agents Limited Credential Networking Params ### Beta Managed Agents Limited Credential Networking Response ### Beta Managed Agents MCP OAuth Auth Response ### Beta Managed Agents MCP OAuth Create Params ### Beta Managed Agents MCP OAuth Refresh Params ### Beta Managed Agents MCP OAuth Refresh Response ### Beta Managed Agents MCP OAuth Refresh Update Params ### Beta Managed Agents MCP OAuth Update Params ### Beta Managed Agents MCP Probe ### Beta Managed Agents Refresh HTTP Response ### Beta Managed Agents Refresh Object ### Beta Managed Agents Static Bearer Auth Response ### Beta Managed Agents Static Bearer Create Params ### Beta Managed Agents Static Bearer Update Params ### Beta Managed Agents Token Endpoint Auth Basic Param ### Beta Managed Agents Token Endpoint Auth Basic Response ### Beta Managed Agents Token Endpoint Auth Basic Update Param ### Beta Managed Agents Token Endpoint Auth None Param ### Beta Managed Agents Token Endpoint Auth None Response ### Beta Managed Agents Token Endpoint Auth Post Param ### Beta Managed Agents Token Endpoint Auth Post Response ### Beta Managed Agents Token Endpoint Auth Post Update Param ### Beta Managed Agents Unrestricted Credential Networking Params ### Beta Managed Agents Unrestricted Credential Networking Response
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: Vaults -url: https://platform.claude.com/docs/en/api/beta/vaults ---- - # Vaults ## Create Vault -**post** `/v1/vaults` +**POST** `/v1/vaults` Create Vault -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `display_name: string` Human-readable name for the vault. 1-255 characters. + minLength: 1, maxLength: 255 + - `metadata: optional map[string]` Arbitrary key-value metadata to attach to the vault. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars. ### Returns -- `BetaManagedAgentsVault object { id, archived_at, created_at, 4 more }` +- `BetaManagedAgentsVault object` A vault that stores credentials for use by agents during sessions.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## List Vaults -**get** `/v1/vaults` +**GET** `/v1/vaults` List Vaults -### Query Parameters +### Query parameters - `include_archived: optional boolean`
Maximum number of vaults to return per page. Defaults to 20, maximum 100. + format: int32 + - `page: optional string` Opaque pagination token from a previous `list_vaults` response. -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `next_page: optional string or null` Pagination token for the next page, or null if no more results. ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Get Vault -**get** `/v1/vaults/{vault_id}` +**GET** `/v1/vaults/{vault_id}` Get Vault -### Path Parameters +### Path parameters - `vault_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsVault object { id, archived_at, created_at, 4 more }` +- `BetaManagedAgentsVault object` A vault that stores credentials for use by agents during sessions.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Update Vault -**post** `/v1/vaults/{vault_id}` +**POST** `/v1/vaults/{vault_id}` Update Vault -### Path Parameters +### Path parameters - `vault_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `display_name: optional string or null` Updated human-readable name for the vault. 1-255 characters. + minLength: 1, maxLength: 255 + - `metadata: optional map[string] or null` Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved. ### Returns -- `BetaManagedAgentsVault object { id, archived_at, created_at, 4 more }` +- `BetaManagedAgentsVault object` A vault that stores credentials for use by agents during sessions.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Delete Vault -**delete** `/v1/vaults/{vault_id}` +**DELETE** `/v1/vaults/{vault_id}` Delete Vault -### Path Parameters +### Path parameters - `vault_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsDeletedVault object { id, type }` +- `BetaManagedAgentsDeletedVault object` Confirmation of a deleted vault.
- `type: "vault_deleted"` - - `"vault_deleted"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Archive Vault -**post** `/v1/vaults/{vault_id}/archive` +**POST** `/v1/vaults/{vault_id}/archive` Archive Vault -### Path Parameters +### Path parameters - `vault_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsVault object { id, archived_at, created_at, 4 more }` +- `BetaManagedAgentsVault object` A vault that stores credentials for use by agents during sessions.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Beta Managed Agents Deleted Vault -- `BetaManagedAgentsDeletedVault object { id, type }` +- `BetaManagedAgentsDeletedVault object` Confirmation of a deleted vault.
- `type: "vault_deleted"` - - `"vault_deleted"` - ### Beta Managed Agents Vault -- `BetaManagedAgentsVault object { id, archived_at, created_at, 4 more }` +- `BetaManagedAgentsVault object` A vault that stores credentials for use by agents during sessions.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string` Human-readable name for the vault.
- `type: "vault"` - - `"vault"` - - `updated_at: string` A timestamp in RFC 3339 format -# Credentials - -## Create Credential - -**post** `/v1/vaults/{vault_id}/credentials` + format: date-time + +## Vaults › Credentials + +### Create Credential + +**POST** `/v1/vaults/{vault_id}/credentials` Create Credential -### Path Parameters +#### Path parameters - `vault_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +#### Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams` Authentication details for creating a credential. - - `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` + - `BetaManagedAgentsMCPOAuthCreateParams object` Parameters for creating an MCP OAuth credential.
OAuth access token. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` Token endpoint uses HTTP Basic authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` Token endpoint uses POST body authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` + minLength: 1, maxLength: 8192 + + - `BetaManagedAgentsStaticBearerCreateParams object` Parameters for creating a static bearer token credential.
Static bearer token value. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` + - `BetaManagedAgentsEnvironmentVariableCreateParams object` Parameters for creating an environment variable credential.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. Immutable after create. + minLength: 1, maxLength: 255 + - `secret_value: string` Secret value. Write-only; never returned in responses. + minLength: 1, maxLength: 4096 + - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` Where in the outbound request the secret value may be substituted.
Human-readable name for the credential. Up to 255 characters. + maxLength: 255 + - `metadata: optional map[string]` Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars. -### Returns - -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +#### Returns + +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## List Credentials - -**get** `/v1/vaults/{vault_id}/credentials` +### List Credentials + +**GET** `/v1/vaults/{vault_id}/credentials` List Credentials -### Path Parameters +#### Path parameters - `vault_id: string` -### Query Parameters +#### Query parameters - `include_archived: optional boolean`
Maximum number of credentials to return per page. Defaults to 20, maximum 100. + format: int32 + - `page: optional string` Opaque pagination token from a previous `list_credentials` response. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +#### Returns - `data: optional array of BetaManagedAgentsCredential`
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Pagination token for the next page, or null if no more results. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Get Credential - -**get** `/v1/vaults/{vault_id}/credentials/{credential_id}` +### Get Credential + +**GET** `/v1/vaults/{vault_id}/credentials/{credential_id}` Get Credential -### Path Parameters +#### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns - -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +#### Returns + +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Update Credential - -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}` +### Update Credential + +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}` Update Credential -### Path Parameters +#### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +#### Body parameters - `auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams` Updated authentication details for a credential. - - `BetaManagedAgentsMCPOAuthUpdateParams object { type, access_token, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthUpdateParams object` Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable. - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `access_token: optional string or null` Updated OAuth access token. + minLength: 1, maxLength: 8192 + - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null` Parameters for updating OAuth refresh token configuration.
Updated OAuth refresh token. + minLength: 1, maxLength: 4096 + - `scope: optional string or null` Updated OAuth scope for the refresh request. + maxLength: 8192 + - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` Updated HTTP Basic authentication parameters for the token endpoint. - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` + - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsStaticBearerUpdateParams object { type, token }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsStaticBearerUpdateParams object` Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable. - `type: "static_bearer"` - - `"static_bearer"` - - `token: optional string or null` Updated static bearer token value. - - `BetaManagedAgentsEnvironmentVariableUpdateParams object { type, injection_location, networking, secret_value }` + minLength: 1, maxLength: 8192 + + - `BetaManagedAgentsEnvironmentVariableUpdateParams object` Parameters for updating an environment variable credential. `secret_name` is immutable. - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams` Updated injection location.
Updated networking scope. Full replacement. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_value: optional string or null` Updated secret value. + minLength: 1, maxLength: 4096 + - `display_name: optional string or null` Updated human-readable name for the credential. 1-255 characters. + minLength: 1, maxLength: 255 + - `metadata: optional map[string] or null` Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved. -### Returns - -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +#### Returns + +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Delete Credential - -**delete** `/v1/vaults/{vault_id}/credentials/{credential_id}` +### Delete Credential + +**DELETE** `/v1/vaults/{vault_id}/credentials/{credential_id}` Delete Credential -### Path Parameters +#### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns - -- `BetaManagedAgentsDeletedCredential object { id, type }` +#### Returns + +- `BetaManagedAgentsDeletedCredential object` Confirmation of a deleted credential.
- `type: "vault_credential_deleted"` - - `"vault_credential_deleted"` - -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Archive Credential - -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}/archive` +### Archive Credential + +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}/archive` Archive Credential -### Path Parameters +#### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns - -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +#### Returns + +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Validate Credential - -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}/mcp_oauth_validate` +### Validate Credential + +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}/mcp_oauth_validate` Validate Credential -### Path Parameters +#### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns - -- `BetaManagedAgentsCredentialValidation object { credential_id, has_refresh_token, mcp_probe, 5 more }` +#### Returns + +- `BetaManagedAgentsCredentialValidation object` Result of live-probing a credential against its configured MCP server.
HTTP status code. + format: int32 + - `method: string` The MCP method that failed (for example `initialize` or `tools/list`).
- `type: "vault_credential_validation"` - - `"vault_credential_validation"` - - `validated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault containing the credential. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/mcp_oauth_validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
"vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv" } ``` - -## Domain Types - -### Beta Managed Agents Credential - -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` - - A credential stored in a vault. Sensitive fields are never returned in responses. - - - `id: string` - - Unique identifier for the credential. - - - `archived_at: string or null` - - A timestamp in RFC 3339 format - - - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` - - Authentication details for a credential. - - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` - - OAuth credential details for an MCP server. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "mcp_oauth"` - - - `"mcp_oauth"` - - - `expires_at: optional string or null` - - A timestamp in RFC 3339 format - - - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` - - OAuth refresh token configuration returned in credential responses. - - - `client_id: string` - - OAuth client ID. - - - `token_endpoint: string` - - Token endpoint URL used to refresh the access token. - - - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse` - - Token endpoint requires no client authentication. - - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - - Token endpoint uses POST body authentication with client credentials. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `resource: optional string or null` - - OAuth resource indicator. - - - `scope: optional string or null` - - OAuth scope for the refresh request. - - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` - - Static bearer token credential details for an MCP server. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "static_bearer"` - - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - - Environment variable credential details. The secret value is never returned. - - - `injection_location: BetaManagedAgentsInjectionLocationResponse` - - Where in the outbound request the secret value is substituted. - - - `body: boolean` - - Whether the placeholder is substituted in the request body. - - - `header: boolean` - - Whether the placeholder is substituted in request header values. - - - `networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse` - - Outbound hosts the secret value is substituted on. - - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` - - The secret is substituted on any host the session's Environment network policy permits egress to. - - - `type: "unrestricted"` - - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - - The secret is substituted only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. An entry matches the request host exactly; a `*.`-prefixed entry matches any subdomain of the named domain but not the domain itself. - - - `type: "limited"` - - - `"limited"` - - - `secret_name: string` - - Name of the environment variable. - - - `type: "environment_variable"` - - - `"environment_variable"` - - - `created_at: string` - - A timestamp in RFC 3339 format - - - `metadata: map[string]` - - Arbitrary key-value metadata attached to the credential. - - - `type: "vault_credential"` - - - `"vault_credential"` - - - `updated_at: string` - - A timestamp in RFC 3339 format - - - `vault_id: string` - - Identifier of the vault this credential belongs to. - - - `display_name: optional string or null` - - Human-readable name for the credential. - -### Beta Managed Agents Credential Networking Params - -- `BetaManagedAgentsCredentialNetworkingParams = BetaManagedAgentsUnrestrictedCredentialNetworkingParams or BetaManagedAgentsLimitedCredentialNetworkingParams` - - Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` - - Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - - `type: "unrestricted"` - - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - - Substitute the secret only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. Each entry is a bare hostname (`api.example.com`), an IPv4 address (`192.0.2.1`), or a `*.`-prefixed wildcard (`*.example.com`). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries. - - - `type: "limited"` - - - `"limited"` - -### Beta Managed Agents Credential Validation - -- `BetaManagedAgentsCredentialValidation object { credential_id, has_refresh_token, mcp_probe, 5 more }` - - Result of live-probing a credential against its configured MCP server. - - - `credential_id: string` - - Unique identifier of the credential that was validated. - - - `has_refresh_token: boolean` - - Whether the credential has a refresh token configured. - - - `mcp_probe: BetaManagedAgentsMCPProbe or null` - - The failing step of an MCP validation probe. - - - `http_response: BetaManagedAgentsRefreshHTTPResponse or null` - - An HTTP response captured during a credential validation probe. - - - `body: string` - - Response body. May be truncated and has sensitive values scrubbed. - - - `body_truncated: boolean` - - Whether `body` was truncated. - - - `content_type: string` - - Value of the `Content-Type` response header. - - - `status_code: number` - - HTTP status code. - - - `method: string` - - The MCP method that failed (for example `initialize` or `tools/list`). - - - `refresh: BetaManagedAgentsRefreshObject or null` - - Outcome of a refresh-token exchange attempted during credential validation. - - - `http_response: BetaManagedAgentsRefreshHTTPResponse or null` - - An HTTP response captured during a credential validation probe. - - - `status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"` - - Outcome of a refresh-token exchange attempted during credential validation. - - - `"succeeded"` - - - `"failed"` - - - `"connect_error"` - - - `"no_refresh_token"` - - - `status: BetaManagedAgentsCredentialValidationStatus` - - Overall verdict of a credential validation probe. - - - `"valid"` - - - `"invalid"` - - - `"unknown"` - - - `type: "vault_credential_validation"` - - - `"vault_credential_validation"` - - - `validated_at: string` - - A timestamp in RFC 3339 format - - - `vault_id: string` - - Identifier of the vault containing the credential. - -### Beta Managed Agents Credential Validation Status - -- `BetaManagedAgentsCredentialValidationStatus = "valid" or "invalid" or "unknown"` - - Overall verdict of a credential validation probe. - - - `"valid"` - - - `"invalid"` - - - `"unknown"` - -### Beta Managed Agents Deleted Credential - -- `BetaManagedAgentsDeletedCredential object { id, type }` - - Confirmation of a deleted credential. - - - `id: string` - - Unique identifier of the deleted credential. - - - `type: "vault_credential_deleted"` - - - `"vault_credential_deleted"` - -### Beta Managed Agents Environment Variable Auth Response - -- `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - - Environment variable credential details. The secret value is never returned. - - - `injection_location: BetaManagedAgentsInjectionLocationResponse` - - Where in the outbound request the secret value is substituted. - - - `body: boolean` - - Whether the placeholder is substituted in the request body. - - - `header: boolean` - - Whether the placeholder is substituted in request header values. - - - `networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse` - - Outbound hosts the secret value is substituted on. - - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` - - The secret is substituted on any host the session's Environment network policy permits egress to. - - - `type: "unrestricted"` - - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - - The secret is substituted only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. An entry matches the request host exactly; a `*.`-prefixed entry matches any subdomain of the named domain but not the domain itself. - - - `type: "limited"` - - - `"limited"` - - - `secret_name: string` - - Name of the environment variable. - - - `type: "environment_variable"` - - - `"environment_variable"` - -### Beta Managed Agents Environment Variable Create Params - -- `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` - - Parameters for creating an environment variable credential. - - - `networking: BetaManagedAgentsCredentialNetworkingParams` - - Outbound hosts the secret value is substituted on. - - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` - - Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - - `type: "unrestricted"` - - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - - Substitute the secret only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. Each entry is a bare hostname (`api.example.com`), an IPv4 address (`192.0.2.1`), or a `*.`-prefixed wildcard (`*.example.com`). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries. - - - `type: "limited"` - - - `"limited"` - - - `secret_name: string` - - Name of the environment variable. Immutable after create. - - - `secret_value: string` - - Secret value. Write-only; never returned in responses. - - - `type: "environment_variable"` - - - `"environment_variable"` - - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` - - Where in the outbound request the secret value may be substituted. - - - `body: optional boolean` - - Substitute when the placeholder appears in the request body. - - - `header: optional boolean` - - Substitute when the placeholder appears in a request header value. - -### Beta Managed Agents Environment Variable Update Params - -- `BetaManagedAgentsEnvironmentVariableUpdateParams object { type, injection_location, networking, secret_value }` - - Parameters for updating an environment variable credential. `secret_name` is immutable. - - - `type: "environment_variable"` - - - `"environment_variable"` - - - `injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams` - - Updated injection location. - - - `body: optional boolean` - - Substitute when the placeholder appears in the request body. - - - `header: optional boolean` - - Substitute when the placeholder appears in a request header value. - - - `networking: optional BetaManagedAgentsCredentialNetworkingParams or null` - - Updated networking scope. Full replacement. - - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` - - Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - - `type: "unrestricted"` - - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - - Substitute the secret only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. Each entry is a bare hostname (`api.example.com`), an IPv4 address (`192.0.2.1`), or a `*.`-prefixed wildcard (`*.example.com`). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries. - - - `type: "limited"` - - - `"limited"` - - - `secret_value: optional string or null` - - Updated secret value. - -### Beta Managed Agents Injection Location Params - -- `BetaManagedAgentsInjectionLocationParams object { body, header }` - - Where in the outbound request the secret value may be substituted. - - - `body: optional boolean` - - Substitute when the placeholder appears in the request body. - - - `header: optional boolean` - - Substitute when the placeholder appears in a request header value. - -### Beta Managed Agents Injection Location Response - -- `BetaManagedAgentsInjectionLocationResponse object { body, header }` - - Where in the outbound request the secret value is substituted. - - - `body: boolean` - - Whether the placeholder is substituted in the request body. - - - `header: boolean` - - Whether the placeholder is substituted in request header values. - -### Beta Managed Agents Injection Location Update Params - -- `BetaManagedAgentsInjectionLocationUpdateParams object { body, header }` - - Updated injection location. - - - `body: optional boolean` - - Substitute when the placeholder appears in the request body. - - - `header: optional boolean` - - Substitute when the placeholder appears in a request header value. - -### Beta Managed Agents Limited Credential Networking Params - -- `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - - Substitute the secret only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. Each entry is a bare hostname (`api.example.com`), an IPv4 address (`192.0.2.1`), or a `*.`-prefixed wildcard (`*.example.com`). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries. - - - `type: "limited"` - - - `"limited"` - -### Beta Managed Agents Limited Credential Networking Response - -- `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - - The secret is substituted only on requests to the listed hosts. - - - `allowed_hosts: array of string` - - Hostnames on which the secret will be substituted. An entry matches the request host exactly; a `*.`-prefixed entry matches any subdomain of the named domain but not the domain itself. - - - `type: "limited"` - - - `"limited"` - -### Beta Managed Agents MCP OAuth Auth Response - -- `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` - - OAuth credential details for an MCP server. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "mcp_oauth"` - - - `"mcp_oauth"` - - - `expires_at: optional string or null` - - A timestamp in RFC 3339 format - - - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` - - OAuth refresh token configuration returned in credential responses. - - - `client_id: string` - - OAuth client ID. - - - `token_endpoint: string` - - Token endpoint URL used to refresh the access token. - - - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse` - - Token endpoint requires no client authentication. - - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - - Token endpoint uses POST body authentication with client credentials. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `resource: optional string or null` - - OAuth resource indicator. - - - `scope: optional string or null` - - OAuth scope for the refresh request. - -### Beta Managed Agents MCP OAuth Create Params - -- `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` - - Parameters for creating an MCP OAuth credential. - - - `access_token: string` - - OAuth access token. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "mcp_oauth"` - - - `"mcp_oauth"` - - - `expires_at: optional string or null` - - A timestamp in RFC 3339 format - - - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` - - OAuth refresh token parameters for creating a credential with refresh support. - - - `client_id: string` - - OAuth client ID. - - - `refresh_token: string` - - OAuth refresh token. - - - `token_endpoint: string` - - Token endpoint URL used to refresh the access token. - - - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` - - Token endpoint requires no client authentication. - - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` - - Token endpoint uses POST body authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `resource: optional string or null` - - OAuth resource indicator. - - - `scope: optional string or null` - - OAuth scope for the refresh request. - -### Beta Managed Agents MCP OAuth Refresh Params - -- `BetaManagedAgentsMCPOAuthRefreshParams object { client_id, refresh_token, token_endpoint, 3 more }` - - OAuth refresh token parameters for creating a credential with refresh support. - - - `client_id: string` - - OAuth client ID. - - - `refresh_token: string` - - OAuth refresh token. - - - `token_endpoint: string` - - Token endpoint URL used to refresh the access token. - - - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` - - Token endpoint requires no client authentication. - - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` - - Token endpoint uses POST body authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `resource: optional string or null` - - OAuth resource indicator. - - - `scope: optional string or null` - - OAuth scope for the refresh request. - -### Beta Managed Agents MCP OAuth Refresh Response - -- `BetaManagedAgentsMCPOAuthRefreshResponse object { client_id, token_endpoint, token_endpoint_auth, 2 more }` - - OAuth refresh token configuration returned in credential responses. - - - `client_id: string` - - OAuth client ID. - - - `token_endpoint: string` - - Token endpoint URL used to refresh the access token. - - - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse` - - Token endpoint requires no client authentication. - - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - - Token endpoint uses POST body authentication with client credentials. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `resource: optional string or null` - - OAuth resource indicator. - - - `scope: optional string or null` - - OAuth scope for the refresh request. - -### Beta Managed Agents MCP OAuth Refresh Update Params - -- `BetaManagedAgentsMCPOAuthRefreshUpdateParams object { refresh_token, scope, token_endpoint_auth }` - - Parameters for updating OAuth refresh token configuration. - - - `refresh_token: optional string or null` - - Updated OAuth refresh token. - - - `scope: optional string or null` - - Updated OAuth scope for the refresh request. - - - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` - - Updated HTTP Basic authentication parameters for the token endpoint. - - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` - - Updated HTTP Basic authentication parameters for the token endpoint. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` - - Updated POST body authentication parameters for the token endpoint. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - -### Beta Managed Agents MCP OAuth Update Params - -- `BetaManagedAgentsMCPOAuthUpdateParams object { type, access_token, expires_at, refresh }` - - Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable. - - - `type: "mcp_oauth"` - - - `"mcp_oauth"` - - - `access_token: optional string or null` - - Updated OAuth access token. - - - `expires_at: optional string or null` - - A timestamp in RFC 3339 format - - - `refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null` - - Parameters for updating OAuth refresh token configuration. - - - `refresh_token: optional string or null` - - Updated OAuth refresh token. - - - `scope: optional string or null` - - Updated OAuth scope for the refresh request. - - - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` - - Updated HTTP Basic authentication parameters for the token endpoint. - - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` - - Updated HTTP Basic authentication parameters for the token endpoint. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` - - Updated POST body authentication parameters for the token endpoint. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - -### Beta Managed Agents MCP Probe - -- `BetaManagedAgentsMCPProbe object { http_response, method }` - - The failing step of an MCP validation probe. - - - `http_response: BetaManagedAgentsRefreshHTTPResponse or null` - - An HTTP response captured during a credential validation probe. - - - `body: string` - - Response body. May be truncated and has sensitive values scrubbed. - - - `body_truncated: boolean` - - Whether `body` was truncated. - - - `content_type: string` - - Value of the `Content-Type` response header. - - - `status_code: number` - - HTTP status code. - - - `method: string` - - The MCP method that failed (for example `initialize` or `tools/list`). - -### Beta Managed Agents Refresh HTTP Response - -- `BetaManagedAgentsRefreshHTTPResponse object { body, body_truncated, content_type, status_code }` - - An HTTP response captured during a credential validation probe. - - - `body: string` - - Response body. May be truncated and has sensitive values scrubbed. - - - `body_truncated: boolean` - - Whether `body` was truncated. - - - `content_type: string` - - Value of the `Content-Type` response header. - - - `status_code: number` - - HTTP status code. - -### Beta Managed Agents Refresh Object - -- `BetaManagedAgentsRefreshObject object { http_response, status }` - - Outcome of a refresh-token exchange attempted during credential validation. - - - `http_response: BetaManagedAgentsRefreshHTTPResponse or null` - - An HTTP response captured during a credential validation probe. - - - `body: string` - - Response body. May be truncated and has sensitive values scrubbed. - - - `body_truncated: boolean` - - Whether `body` was truncated. - - - `content_type: string` - - Value of the `Content-Type` response header. - - - `status_code: number` - - HTTP status code. - - - `status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"` - - Outcome of a refresh-token exchange attempted during credential validation. - - - `"succeeded"` - - - `"failed"` - - - `"connect_error"` - - - `"no_refresh_token"` - -### Beta Managed Agents Static Bearer Auth Response - -- `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` - - Static bearer token credential details for an MCP server. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "static_bearer"` - - - `"static_bearer"` - -### Beta Managed Agents Static Bearer Create Params - -- `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` - - Parameters for creating a static bearer token credential. - - - `token: string` - - Static bearer token value. - - - `mcp_server_url: string` - - URL of the MCP server this credential authenticates against. - - - `type: "static_bearer"` - - - `"static_bearer"` - -### Beta Managed Agents Static Bearer Update Params - -- `BetaManagedAgentsStaticBearerUpdateParams object { type, token }` - - Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable. - - - `type: "static_bearer"` - - - `"static_bearer"` - - - `token: optional string or null` - - Updated static bearer token value. - -### Beta Managed Agents Token Endpoint Auth Basic Param - -- `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - -### Beta Managed Agents Token Endpoint Auth Basic Response - -- `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - - Token endpoint uses HTTP Basic authentication with client credentials. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - -### Beta Managed Agents Token Endpoint Auth Basic Update Param - -- `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` - - Updated HTTP Basic authentication parameters for the token endpoint. - - - `type: "client_secret_basic"` - - - `"client_secret_basic"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - -### Beta Managed Agents Token Endpoint Auth None Param - -- `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - -### Beta Managed Agents Token Endpoint Auth None Response - -- `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` - - Token endpoint requires no client authentication. - - - `type: "none"` - - - `"none"` - -### Beta Managed Agents Token Endpoint Auth Post Param - -- `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` - - Token endpoint uses POST body authentication with client credentials. - - - `client_secret: string` - - OAuth client secret. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - -### Beta Managed Agents Token Endpoint Auth Post Response - -- `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - - Token endpoint uses POST body authentication with client credentials. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - -### Beta Managed Agents Token Endpoint Auth Post Update Param - -- `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` - - Updated POST body authentication parameters for the token endpoint. - - - `type: "client_secret_post"` - - - `"client_secret_post"` - - - `client_secret: optional string or null` - - Updated OAuth client secret. - -### Beta Managed Agents Unrestricted Credential Networking Params - -- `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` - - Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - - `type: "unrestricted"` - - - `"unrestricted"` - -### Beta Managed Agents Unrestricted Credential Networking Response - -- `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` - - The secret is substituted on any host the session's Environment network policy permits egress to. - - - `type: "unrestricted"` - - - `"unrestricted"`