Create Credential
api/beta/vaults/credentials/create
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/vaults/credentials/create Changed · +67 / -68 lines
# Create Credential ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200) ## Create Credential ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
---- -title: Create Credential -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/create ---- +# Create Credential -## Create Credential +**POST** `/v1/vaults/{vault_id}/credentials` -**post** `/v1/vaults/{vault_id}/credentials` - Create Credential -### Path Parameters +## Path parameters - `vault_id: string` -### Header Parameters +## Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +## Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams` Authentication details for creating a credential. - - `BetaManagedAgentsMCPOAuthCreateParams object { access_token, mcp_server_url, type, 2 more }` + - `BetaManagedAgentsMCPOAuthCreateParams object` Parameters for creating an MCP OAuth credential.
OAuth access token. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null` OAuth refresh token parameters for creating a credential with refresh support.
OAuth client ID. + minLength: 1, maxLength: 1024 + - `refresh_token: string` OAuth refresh token. + minLength: 1, maxLength: 4096 + - `token_endpoint: string` Token endpoint URL used to refresh the access token. + minLength: 1, maxLength: 2047 + - `token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam` Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneParam object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneParam object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicParam object` - - `BetaManagedAgentsTokenEndpointAuthBasicParam object { client_secret, type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `client_secret: string`
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostParam object` - - `BetaManagedAgentsTokenEndpointAuthPostParam object { client_secret, type }` - Token endpoint uses POST body authentication with client credentials. - `client_secret: string`
OAuth client secret. + minLength: 1, maxLength: 512 + - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator. + minLength: 1, maxLength: 2047 + - `scope: optional string or null` OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerCreateParams object { token, mcp_server_url, type }` + minLength: 1, maxLength: 8192 + - `BetaManagedAgentsStaticBearerCreateParams object` + Parameters for creating a static bearer token credential. - `token: string`
Static bearer token value. + minLength: 1, maxLength: 8192 + - `mcp_server_url: string` URL of the MCP server this credential authenticates against. + minLength: 1, maxLength: 2047 + - `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableCreateParams object` - - `BetaManagedAgentsEnvironmentVariableCreateParams object { networking, secret_name, secret_value, 2 more }` - Parameters for creating an environment variable credential. - `networking: BetaManagedAgentsCredentialNetworkingParams`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingParams object` Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingParams object` - - `BetaManagedAgentsLimitedCredentialNetworkingParams object { allowed_hosts, type }` - Substitute the secret only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable. Immutable after create. + minLength: 1, maxLength: 255 + - `secret_value: string` Secret value. Write-only; never returned in responses. + minLength: 1, maxLength: 4096 + - `type: "environment_variable"` - - `"environment_variable"` - - `injection_location: optional BetaManagedAgentsInjectionLocationParams` Where in the outbound request the secret value may be substituted.
Human-readable name for the credential. Up to 255 characters. + maxLength: 255 + - `metadata: optional map[string]` Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars. -### Returns +## Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - Environment variable credential details. The secret value is never returned. - `injection_location: BetaManagedAgentsInjectionLocationResponse`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - The secret is substituted only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable.
- `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +### Response (200) ```json {