Get Credential
api/beta/vaults/credentials/retrieve
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/vaults/credentials/retrieve Changed · +28 / -43 lines
# Get Credential ## Path parameters ## Headers ## Returns ## Example ### Response (200) ## Get Credential ### Path Parameters ### Header Parameters ### Returns ### Example #### Response
---- -title: Get Credential -url: https://platform.claude.com/docs/en/api/beta/vaults/credentials/retrieve ---- +# Get Credential -## Get Credential +**GET** `/v1/vaults/{vault_id}/credentials/{credential_id}` -**get** `/v1/vaults/{vault_id}/credentials/{credential_id}` - Get Credential -### Path Parameters +## Path parameters - `vault_id: string` - `credential_id: string` -### Header Parameters +## Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +## Returns -- `BetaManagedAgentsCredential object { id, archived_at, auth, 6 more }` +- `BetaManagedAgentsCredential object` A credential stored in a vault. Sensitive fields are never returned in responses.
A timestamp in RFC 3339 format + format: date-time + - `auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse` Authentication details for a credential. - - `BetaManagedAgentsMCPOAuthAuthResponse object { mcp_server_url, type, expires_at, refresh }` + - `BetaManagedAgentsMCPOAuthAuthResponse object` OAuth credential details for an MCP server.
- `type: "mcp_oauth"` - - `"mcp_oauth"` - - `expires_at: optional string or null` A timestamp in RFC 3339 format + format: date-time + - `refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null` OAuth refresh token configuration returned in credential responses.
Token endpoint requires no client authentication. - - `BetaManagedAgentsTokenEndpointAuthNoneResponse object { type }` + - `BetaManagedAgentsTokenEndpointAuthNoneResponse object` Token endpoint requires no client authentication. - `type: "none"` - - `"none"` + - `BetaManagedAgentsTokenEndpointAuthBasicResponse object` - - `BetaManagedAgentsTokenEndpointAuthBasicResponse object { type }` - Token endpoint uses HTTP Basic authentication with client credentials. - `type: "client_secret_basic"` - - `"client_secret_basic"` + - `BetaManagedAgentsTokenEndpointAuthPostResponse object` - - `BetaManagedAgentsTokenEndpointAuthPostResponse object { type }` - Token endpoint uses POST body authentication with client credentials. - `type: "client_secret_post"` - - `"client_secret_post"` - - `resource: optional string or null` OAuth resource indicator.
OAuth scope for the refresh request. - - `BetaManagedAgentsStaticBearerAuthResponse object { mcp_server_url, type }` + - `BetaManagedAgentsStaticBearerAuthResponse object` Static bearer token credential details for an MCP server.
- `type: "static_bearer"` - - `"static_bearer"` + - `BetaManagedAgentsEnvironmentVariableAuthResponse object` - - `BetaManagedAgentsEnvironmentVariableAuthResponse object { injection_location, networking, secret_name, type }` - Environment variable credential details. The secret value is never returned. - `injection_location: BetaManagedAgentsInjectionLocationResponse`
Outbound hosts the secret value is substituted on. - - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object { type }` + - `BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object` The secret is substituted on any host the session's Environment network policy permits egress to. - `type: "unrestricted"` - - `"unrestricted"` + - `BetaManagedAgentsLimitedCredentialNetworkingResponse object` - - `BetaManagedAgentsLimitedCredentialNetworkingResponse object { allowed_hosts, type }` - The secret is substituted only on requests to the listed hosts. - `allowed_hosts: array of string`
- `type: "limited"` - - `"limited"` - - `secret_name: string` Name of the environment variable.
- `type: "environment_variable"` - - `"environment_variable"` - - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `metadata: map[string]` Arbitrary key-value metadata attached to the credential.
- `type: "vault_credential"` - - `"vault_credential"` - - `updated_at: string` A timestamp in RFC 3339 format + format: date-time + - `vault_id: string` Identifier of the vault this credential belongs to.
Human-readable name for the credential. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: managed-agents-2026-04-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +### Response (200) ```json {