Credentials
api/beta/vaults/credentials
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/vaults/credentials Changed · +353 / -406 lines
### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: Credentials -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials ---- - # Credentials ## Create Credential -**post** `/v1/vaults/{vault_id}/credentials` +**POST** `/v1/vaults/{vault_id}/credentials` Create Credential -### Path Parameters +### Path parameters - `vault_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams` Authentication details for creating a credential. - - `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` + - `BetaManagedAgentsMCPOAuthCreateParams object` Parameters for creating an MCP OAuth credential.
OAuth access token. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` Token endpoint uses HTTP Basic authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` Token endpoint uses POST body authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` + minLength: 1, maxLength: 8192 + + - `BetaManagedAgentsStaticBearerCreateParams object` Parameters for creating a static bearer token credential.
Static bearer token value. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` + - `BetaManagedAgentsEnvironmentVariableCreateParams object` Parameters for creating an environment variable credential.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. Immutable after create. + minLength: 1, maxLength: 255 + - `secret_value: string` Secret value. Write-only; never returned in responses. + minLength: 1, maxLength: 4096 + - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` Where in the outbound request the secret value may be substituted.
Human-readable name for the credential. Up to 255 characters. + maxLength: 255 + - `metadata: optional map[string]` Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars. ### Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## List Credentials -**get** `/v1/vaults/{vault_id}/credentials` +**GET** `/v1/vaults/{vault_id}/credentials` List Credentials -### Path Parameters +### Path parameters - `vault_id: string` -### Query Parameters +### Query parameters - `include_archived: optional boolean`
Maximum number of credentials to return per page. Defaults to 20, maximum 100. + format: int32 + - `page: optional string` Opaque pagination token from a previous `list_credentials` response. -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Get Credential -**get** `/v1/vaults/{vault_id}/credentials/{credential_id}` +**GET** `/v1/vaults/{vault_id}/credentials/{credential_id}` Get Credential -### Path Parameters +### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \ -H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Update Credential -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}` +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}` Update Credential -### Path Parameters +### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams` Updated authentication details for a credential. - - `BetaManagedAgentsMCPOAuthUpdateParams object { type, access_token, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthUpdateParams object` Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable. - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `access_token: optional string or null` Updated OAuth access token. + minLength: 1, maxLength: 8192 + - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null` Parameters for updating OAuth refresh token configuration.
Updated OAuth refresh token. + minLength: 1, maxLength: 4096 + - `scope: optional string or null` Updated OAuth scope for the refresh request. + maxLength: 8192 + - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` Updated HTTP Basic authentication parameters for the token endpoint. - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` + - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsStaticBearerUpdateParams object { type, token }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsStaticBearerUpdateParams object` Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable. - `type: "static_bearer"` - - `"static_bearer"` - - `token: optional string or null` Updated static bearer token value. - - `BetaManagedAgentsEnvironmentVariableUpdateParams object { type, injection_location, networking, secret_value }` + minLength: 1, maxLength: 8192 + + - `BetaManagedAgentsEnvironmentVariableUpdateParams object` Parameters for updating an environment variable credential. `secret_name` is immutable. - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams` Updated injection location.
Updated networking scope. Full replacement. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_value: optional string or null` Updated secret value. + minLength: 1, maxLength: 4096 + - `display_name: optional string or null` Updated human-readable name for the credential. 1-255 characters. + minLength: 1, maxLength: 255 + - `metadata: optional map[string] or null` Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved. ### Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Delete Credential -**delete** `/v1/vaults/{vault_id}/credentials/{credential_id}` +**DELETE** `/v1/vaults/{vault_id}/credentials/{credential_id}` Delete Credential -### Path Parameters +### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsDeletedCredential object { id, type }` +- `BetaManagedAgentsDeletedCredential object` Confirmation of a deleted credential.
- `type: "vault_credential_deleted"` - - `"vault_credential_deleted"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Archive Credential -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}/archive` +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}/archive` Archive Credential -### Path Parameters +### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Validate Credential -**post** `/v1/vaults/{vault_id}/credentials/{credential_id}/mcp_oauth_validate` +**POST** `/v1/vaults/{vault_id}/credentials/{credential_id}/mcp_oauth_validate` Validate Credential -### Path Parameters +### Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaManagedAgentsCredentialValidation object { credential_id, has_refresh_token, mcp_probe, 5 more }` +- `BetaManagedAgentsCredentialValidation object` Result of live-probing a credential against its configured MCP server.
HTTP status code. + format: int32 + - `method: string` The MCP method that failed (for example `initialize` or `tools/list`).
- `type: "vault_credential_validation"` - - `"vault_credential_validation"` - - `validated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault containing the credential. ### Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/mcp_oauth_validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Beta Managed Agents Credential -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential. - `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - ### Beta Managed Agents Credential Validation -- `BetaManagedAgentsCredentialValidation object { credential_id, has_refresh_token, mcp_probe, 5 more }` +- `BetaManagedAgentsCredentialValidation object` Result of live-probing a credential against its configured MCP server.
HTTP status code. + format: int32 + - `method: string` The MCP method that failed (for example `initialize` or `tools/list`).
- `type: "vault_credential_validation"` - - `"vault_credential_validation"` - - `validated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault containing the credential.
### Beta Managed Agents Deleted Credential -- `BetaManagedAgentsDeletedCredential object { id, type }` +- `BetaManagedAgentsDeletedCredential object` Confirmation of a deleted credential.
- `type: "vault_credential_deleted"` - - `"vault_credential_deleted"` - ### Beta Managed Agents Environment Variable Auth Response -- `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` +- `BetaManagedAgentsEnvironmentVariableAuthResponse object` Environment variable credential details. The secret value is never returned.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. - `type: "environment_variable"` - - `"environment_variable"` - ### Beta Managed Agents Environment Variable Create Params -- `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` +- `BetaManagedAgentsEnvironmentVariableCreateParams object` Parameters for creating an environment variable credential.
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. Immutable after create. + minLength: 1, maxLength: 255 + - `secret_value: string` Secret value. Write-only; never returned in responses. + minLength: 1, maxLength: 4096 + - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` Where in the outbound request the secret value may be substituted.
### Beta Managed Agents Environment Variable Update Params -- `BetaManagedAgentsEnvironmentVariableUpdateParams object { type, injection_location, networking, secret_value }` +- `BetaManagedAgentsEnvironmentVariableUpdateParams object` Parameters for updating an environment variable credential. `secret_name` is immutable. - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams` Updated injection location.
Updated networking scope. Full replacement. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - - `secret_value: optional string or null` Updated secret value. + minLength: 1, maxLength: 4096 + ### Beta Managed Agents Injection Location Params -- `BetaManagedAgentsInjectionLocationParams object { body, header }` +- `BetaManagedAgentsInjectionLocationParams object` Where in the outbound request the secret value may be substituted.
### Beta Managed Agents Injection Location Response -- `BetaManagedAgentsInjectionLocationResponse object { body, header }` +- `BetaManagedAgentsInjectionLocationResponse object` Where in the outbound request the secret value is substituted.
### Beta Managed Agents Injection Location Update Params -- `BetaManagedAgentsInjectionLocationUpdateParams object { body, header }` +- `BetaManagedAgentsInjectionLocationUpdateParams object` Updated injection location.
### Beta Managed Agents Limited Credential Networking Params -- `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` +- `BetaManagedAgentsLimitedCredentialNetworkingParams object` Substitute the secret only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - ### Beta Managed Agents Limited Credential Networking Response -- `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` +- `BetaManagedAgentsLimitedCredentialNetworkingResponse object` The secret is substituted only on requests to the listed hosts.
- `type: "limited"` - - `"limited"` - ### Beta Managed Agents MCP OAuth Auth Response -- `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` +- `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
### Beta Managed Agents MCP OAuth Create Params -- `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` +- `BetaManagedAgentsMCPOAuthCreateParams object` Parameters for creating an MCP OAuth credential.
OAuth access token. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` Token endpoint uses HTTP Basic authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` Token endpoint uses POST body authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. + minLength: 1, maxLength: 8192 + ### Beta Managed Agents MCP OAuth Refresh Params -- `BetaManagedAgentsMCPOAuthRefreshParams object { client_id, refresh_token, token_endpoint, 3 more }` +- `BetaManagedAgentsMCPOAuthRefreshParams object` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` Token endpoint uses HTTP Basic authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` Token endpoint uses POST body authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. + minLength: 1, maxLength: 8192 + ### Beta Managed Agents MCP OAuth Refresh Response -- `BetaManagedAgentsMCPOAuthRefreshResponse object { client_id, token_endpoint, token_endpoint_auth, 2 more }` +- `BetaManagedAgentsMCPOAuthRefreshResponse object` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
### Beta Managed Agents MCP OAuth Refresh Update Params -- `BetaManagedAgentsMCPOAuthRefreshUpdateParams object { refresh_token, scope, token_endpoint_auth }` +- `BetaManagedAgentsMCPOAuthRefreshUpdateParams object` Parameters for updating OAuth refresh token configuration.
Updated OAuth refresh token. + minLength: 1, maxLength: 4096 + - `scope: optional string or null` Updated OAuth scope for the refresh request. + maxLength: 8192 + - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` Updated HTTP Basic authentication parameters for the token endpoint. - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` + - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. + minLength: 1, maxLength: 512 + ### Beta Managed Agents MCP OAuth Update Params -- `BetaManagedAgentsMCPOAuthUpdateParams object { type, access_token, expires_at, refresh }` +- `BetaManagedAgentsMCPOAuthUpdateParams object` Parameters for updating an MCP OAuth credential. The `mcp_server_url` is immutable. - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `access_token: optional string or null` Updated OAuth access token. + minLength: 1, maxLength: 8192 + - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null` Parameters for updating OAuth refresh token configuration.
Updated OAuth refresh token. + minLength: 1, maxLength: 4096 + - `scope: optional string or null` Updated OAuth scope for the refresh request. + maxLength: 8192 + - `token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam` Updated HTTP Basic authentication parameters for the token endpoint. - - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` + - `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. - - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` + minLength: 1, maxLength: 512 + + - `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. + minLength: 1, maxLength: 512 + ### Beta Managed Agents MCP Probe -- `BetaManagedAgentsMCPProbe object { http_response, method }` +- `BetaManagedAgentsMCPProbe object` The failing step of an MCP validation probe.
HTTP status code. + format: int32 + - `method: string` The MCP method that failed (for example `initialize` or `tools/list`). ### Beta Managed Agents Refresh HTTP Response -- `BetaManagedAgentsRefreshHTTPResponse object { body, body_truncated, content_type, status_code }` +- `BetaManagedAgentsRefreshHTTPResponse object` An HTTP response captured during a credential validation probe.
HTTP status code. + format: int32 + ### Beta Managed Agents Refresh Object -- `BetaManagedAgentsRefreshObject object { http_response, status }` +- `BetaManagedAgentsRefreshObject object` Outcome of a refresh-token exchange attempted during credential validation.
HTTP status code. + format: int32 + - `status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"` Outcome of a refresh-token exchange attempted during credential validation.
### Beta Managed Agents Static Bearer Auth Response -- `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` +- `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` - ### Beta Managed Agents Static Bearer Create Params -- `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` +- `BetaManagedAgentsStaticBearerCreateParams object` Parameters for creating a static bearer token credential.
Static bearer token value. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "static_bearer"` - - `"static_bearer"` - ### Beta Managed Agents Static Bearer Update Params -- `BetaManagedAgentsStaticBearerUpdateParams object { type, token }` +- `BetaManagedAgentsStaticBearerUpdateParams object` Parameters for updating a static bearer token credential. The `mcp_server_url` is immutable. - `type: "static_bearer"` - - `"static_bearer"` - - `token: optional string or null` Updated static bearer token value. + minLength: 1, maxLength: 8192 + ### Beta Managed Agents Token Endpoint Auth Basic Param -- `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` +- `BetaManagedAgentsTokenEndpointAuthBasicParam object` Token endpoint uses HTTP Basic authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` - ### Beta Managed Agents Token Endpoint Auth Basic Response -- `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` +- `BetaManagedAgentsTokenEndpointAuthBasicResponse object` Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` - ### Beta Managed Agents Token Endpoint Auth Basic Update Param -- `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object { type, client_secret }` +- `BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object` Updated HTTP Basic authentication parameters for the token endpoint. - `type: "client_secret_basic"` - - `"client_secret_basic"` - - `client_secret: optional string or null` Updated OAuth client secret. + minLength: 1, maxLength: 512 + ### Beta Managed Agents Token Endpoint Auth None Param -- `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` +- `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - ### Beta Managed Agents Token Endpoint Auth None Response -- `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` +- `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` - ### Beta Managed Agents Token Endpoint Auth Post Param -- `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` +- `BetaManagedAgentsTokenEndpointAuthPostParam object` Token endpoint uses POST body authentication with client credentials.
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - ### Beta Managed Agents Token Endpoint Auth Post Response -- `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` +- `BetaManagedAgentsTokenEndpointAuthPostResponse object` Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - ### Beta Managed Agents Token Endpoint Auth Post Update Param -- `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object { type, client_secret }` +- `BetaManagedAgentsTokenEndpointAuthPostUpdateParam object` Updated POST body authentication parameters for the token endpoint. - `type: "client_secret_post"` - - `"client_secret_post"` - - `client_secret: optional string or null` Updated OAuth client secret. + minLength: 1, maxLength: 512 + ### Beta Managed Agents Unrestricted Credential Networking Params -- `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` +- `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` - ### Beta Managed Agents Unrestricted Credential Networking Response -- `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` +- `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - - `"unrestricted"`