Haijun Platform Docs
ID

Create Credential

POST /v1/vaults/{vault_id}/credentials

Create Credential

Path parameters

  • vault_id: string

Identifier of the vault to create the credential in.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Body parameters

  • auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams

Authentication configuration for the credential.

  • BetaManagedAgentsMCPOAuthCreateParams object

Parameters for creating an MCP OAuth credential.

  • type: "mcp_oauth"
  • access_token: string

OAuth access token.

minLength: 1, maxLength: 8192

  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

minLength: 1, maxLength: 2047

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

minLength: 1, maxLength: 1024

  • refresh_token: string

OAuth refresh token.

minLength: 1, maxLength: 8192

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

minLength: 1, maxLength: 2047

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam
  • BetaManagedAgentsTokenEndpointAuthNoneParam object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicParam object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostParam object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • resource: optional string or null

OAuth resource indicator.

minLength: 1, maxLength: 2047

  • scope: optional string or null

OAuth scope for the refresh request.

minLength: 1, maxLength: 8192

  • BetaManagedAgentsStaticBearerCreateParams object

Parameters for creating a static bearer token credential.

  • type: "static_bearer"
  • token: string

Static bearer token value.

minLength: 1, maxLength: 8192

  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

minLength: 1, maxLength: 2047

  • BetaManagedAgentsEnvironmentVariableCreateParams object

Parameters for creating an environment variable credential.

  • type: "environment_variable"
  • networking: BetaManagedAgentsCredentialNetworkingParams

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

  • secret_name: string

Name of the environment variable. Immutable after create.

minLength: 1, maxLength: 255

  • secret_value: string

Secret value. Write-only; never returned in responses.

minLength: 1, maxLength: 4096

  • injection_location: optional BetaManagedAgentsInjectionLocationParams

Where in the outbound request the secret value may be substituted.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

  • display_name: optional string or null

Human-readable name for the credential. Up to 255 characters.

maxLength: 255

  • metadata: optional map[string]

Arbitrary key-value metadata to attach to the credential. Maximum 16 pairs, keys up to 64 chars, values up to 512 chars.

Returns

  • BetaManagedAgentsCredential object

A credential stored in a vault. Sensitive fields are never returned in responses.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "auth": {
            "token": "bearer_exampletoken",
            "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
            "type": "static_bearer"
          },
          "display_name": "Example credential",
          "metadata": {
            "environment": "production"
          }
        }'

Response (200)

json
{
  "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "archived_at": null,
  "auth": {
    "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
    "type": "static_bearer"
  },
  "created_at": "2026-03-15T10:00:00Z",
  "metadata": {
    "environment": "production"
  },
  "type": "vault_credential",
  "updated_at": "2026-03-15T10:00:00Z",
  "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
  "display_name": "Example credential"
}

List Credentials

GET /v1/vaults/{vault_id}/credentials

List Credentials

Path parameters

  • vault_id: string

Identifier of the vault to list credentials for.

Query parameters

  • include_archived: optional boolean

Whether to include archived credentials in the results.

  • limit: optional number

Maximum number of credentials to return per page. Defaults to 20, maximum 100.

format: int32

  • page: optional string

Opaque pagination token from a previous list_credentials response.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • data: optional array of BetaManagedAgentsCredential

List of credentials.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

  • next_page: optional string or null

Pagination token for the next page, or null if no more results.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "data": [
    {
      "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
      "archived_at": null,
      "auth": {
        "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
        "type": "static_bearer"
      },
      "created_at": "2026-03-15T10:00:00Z",
      "metadata": {
        "environment": "production"
      },
      "type": "vault_credential",
      "updated_at": "2026-03-15T10:00:00Z",
      "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
      "display_name": "Example credential"
    }
  ],
  "next_page": "page_MjAyNS0wNS0xNFQwMDowMDowMFo="
}

Get Credential

GET /v1/vaults/{vault_id}/credentials/{credential_id}

Get Credential

Path parameters

  • vault_id: string

Identifier of the vault containing the credential.

  • credential_id: string

Unique identifier of the credential to retrieve.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaManagedAgentsCredential object

A credential stored in a vault. Sensitive fields are never returned in responses.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "archived_at": null,
  "auth": {
    "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
    "type": "static_bearer"
  },
  "created_at": "2026-03-15T10:00:00Z",
  "metadata": {
    "environment": "production"
  },
  "type": "vault_credential",
  "updated_at": "2026-03-15T10:00:00Z",
  "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
  "display_name": "Example credential"
}

Update Credential

POST /v1/vaults/{vault_id}/credentials/{credential_id}

Update Credential

Path parameters

  • vault_id: string

Identifier of the vault containing the credential.

  • credential_id: string

Unique identifier of the credential to update.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Body parameters

  • auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams

Updated authentication configuration. The type is immutable; the variant sent must match the stored credential's type.

  • BetaManagedAgentsMCPOAuthUpdateParams object

Parameters for updating an MCP OAuth credential. The mcp_server_url is immutable.

  • type: "mcp_oauth"
  • access_token: optional string or null

Updated OAuth access token.

minLength: 1, maxLength: 8192

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null

Updated refresh token configuration.

  • refresh_token: optional string or null

Updated OAuth refresh token.

minLength: 1, maxLength: 8192

  • scope: optional string or null

Updated OAuth scope for the refresh request.

maxLength: 8192

  • token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam
  • BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object

Updated HTTP Basic authentication parameters for the token endpoint.

  • type: "client_secret_basic"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostUpdateParam object

Updated POST body authentication parameters for the token endpoint.

  • type: "client_secret_post"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsStaticBearerUpdateParams object

Parameters for updating a static bearer token credential. The mcp_server_url is immutable.

  • type: "static_bearer"
  • token: optional string or null

Updated static bearer token value.

minLength: 1, maxLength: 8192

  • BetaManagedAgentsEnvironmentVariableUpdateParams object

Parameters for updating an environment variable credential. secret_name is immutable.

  • type: "environment_variable"
  • injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams

Updated injection location.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

  • networking: optional BetaManagedAgentsCredentialNetworkingParams or null

Updated networking scope. Full replacement.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

  • secret_value: optional string or null

Updated secret value.

minLength: 1, maxLength: 4096

  • display_name: optional string or null

Updated human-readable name for the credential. 1-255 characters.

minLength: 1, maxLength: 255

  • metadata: optional map[string] or null

Metadata patch. Set a key to a string to upsert it, or to null to delete it. Omitted keys are preserved.

Returns

  • BetaManagedAgentsCredential object

A credential stored in a vault. Sensitive fields are never returned in responses.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "display_name": "Example credential",
          "metadata": {
            "environment": "production"
          }
        }'

Response (200)

json
{
  "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "archived_at": null,
  "auth": {
    "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
    "type": "static_bearer"
  },
  "created_at": "2026-03-15T10:00:00Z",
  "metadata": {
    "environment": "production"
  },
  "type": "vault_credential",
  "updated_at": "2026-03-15T10:00:00Z",
  "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
  "display_name": "Example credential"
}

Delete Credential

DELETE /v1/vaults/{vault_id}/credentials/{credential_id}

Delete Credential

Path parameters

  • vault_id: string

Identifier of the vault containing the credential.

  • credential_id: string

Unique identifier of the credential to delete.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaManagedAgentsDeletedCredential object

Confirmation of a deleted credential.

  • type: "vault_credential_deleted"
  • id: string

Unique identifier of the deleted credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "type": "vault_credential_deleted"
}

Archive Credential

POST /v1/vaults/{vault_id}/credentials/{credential_id}/archive

Archive Credential

Path parameters

  • vault_id: string

Identifier of the vault containing the credential.

  • credential_id: string

Unique identifier of the credential to archive.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaManagedAgentsCredential object

A credential stored in a vault. Sensitive fields are never returned in responses.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/archive \
    -X POST \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "archived_at": null,
  "auth": {
    "mcp_server_url": "https://example-server.modelcontextprotocol.io/sse",
    "type": "static_bearer"
  },
  "created_at": "2026-03-15T10:00:00Z",
  "metadata": {
    "environment": "production"
  },
  "type": "vault_credential",
  "updated_at": "2026-03-15T10:00:00Z",
  "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv",
  "display_name": "Example credential"
}

Validate Credential

POST /v1/vaults/{vault_id}/credentials/{credential_id}/mcp_oauth_validate

Validate Credential

Path parameters

  • vault_id: string

Identifier of the vault containing the credential.

  • credential_id: string

Unique identifier of the credential to validate.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaManagedAgentsCredentialValidation object

Result of live-probing a credential against its configured MCP server.

  • type: "vault_credential_validation"
  • credential_id: string

Unique identifier of the credential that was validated.

  • has_refresh_token: boolean

Whether the credential has a refresh token configured.

  • mcp_probe: BetaManagedAgentsMCPProbe or null

Details of the failing MCP probe step. Null when the probe succeeded.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response. Null when no HTTP response was received (timeout, DNS, TLS).

  • body: string

Response body. May be truncated and has sensitive values scrubbed.

  • body_truncated: boolean

Whether body was truncated.

  • content_type: string

Value of the Content-Type response header.

  • status_code: number

HTTP status code.

format: int32

  • method: string

The MCP method that failed (for example initialize or tools/list).

  • refresh: BetaManagedAgentsRefreshObject or null

Details of the refresh-token exchange attempted on a 401. Null when no refresh was attempted.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response from the token endpoint. Populated only when status is failed.

  • status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"

Outcome of the refresh attempt.

  • "succeeded"

The token endpoint returned a new access token.

  • "failed"

The token endpoint returned an error response. See http_response for detail.

  • "connect_error"

The token endpoint could not be reached (DNS, TLS, or connection error).

  • "no_refresh_token"

No refresh token is stored for the credential, so no exchange was attempted.

  • status: BetaManagedAgentsCredentialValidationStatus

Overall verdict of the validation probe.

  • "valid"

The credential successfully authenticated against its MCP server.

  • "invalid"

The probe reached the MCP server and was rejected, and a refresh (if attempted) did not recover it.

  • "unknown"

The probe could not determine validity — for example, a transport error or a successful refresh that was not re-probed.

  • validated_at: string

When the validation probe was performed.

format: date-time

  • vault_id: string

Identifier of the vault containing the credential.

Example

bash
curl https://haijun.my.id/v1/vaults/$VAULT_ID/credentials/$CREDENTIAL_ID/mcp_oauth_validate \
    -X POST \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: managed-agents-2026-04-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "credential_id": "vcrd_011CZkZEMt8gZan2iYOQfSkw",
  "has_refresh_token": true,
  "mcp_probe": {
    "http_response": {
      "body": "body",
      "body_truncated": true,
      "content_type": "content_type",
      "status_code": 0
    },
    "method": "method"
  },
  "refresh": {
    "http_response": {
      "body": "body",
      "body_truncated": true,
      "content_type": "content_type",
      "status_code": 0
    },
    "status": "succeeded"
  },
  "status": "valid",
  "type": "vault_credential_validation",
  "validated_at": "2026-03-15T10:00:00Z",
  "vault_id": "vlt_011CZkZDLs7fYzm1hXNPeRjv"
}

Domain types

Beta Managed Agents Credential

  • BetaManagedAgentsCredential object

A credential stored in a vault. Sensitive fields are never returned in responses.

  • type: "vault_credential"
  • id: string

Unique identifier for the credential.

  • archived_at: string or null

When the credential was archived. Null if not archived.

format: date-time

  • auth: BetaManagedAgentsMCPOAuthAuthResponse or BetaManagedAgentsStaticBearerAuthResponse or BetaManagedAgentsEnvironmentVariableAuthResponse

Authentication configuration for this credential.

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

  • created_at: string

A timestamp in RFC 3339 format

format: date-time

  • metadata: map[string]

Arbitrary key-value metadata attached to the credential.

  • updated_at: string

A timestamp in RFC 3339 format

format: date-time

  • vault_id: string

Identifier of the vault this credential belongs to.

  • display_name: optional string or null

Human-readable name for the credential.

Beta Managed Agents Credential Networking Params

  • BetaManagedAgentsCredentialNetworkingParams = BetaManagedAgentsUnrestrictedCredentialNetworkingParams or BetaManagedAgentsLimitedCredentialNetworkingParams
  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

Beta Managed Agents Credential Validation

  • BetaManagedAgentsCredentialValidation object

Result of live-probing a credential against its configured MCP server.

  • type: "vault_credential_validation"
  • credential_id: string

Unique identifier of the credential that was validated.

  • has_refresh_token: boolean

Whether the credential has a refresh token configured.

  • mcp_probe: BetaManagedAgentsMCPProbe or null

Details of the failing MCP probe step. Null when the probe succeeded.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response. Null when no HTTP response was received (timeout, DNS, TLS).

  • body: string

Response body. May be truncated and has sensitive values scrubbed.

  • body_truncated: boolean

Whether body was truncated.

  • content_type: string

Value of the Content-Type response header.

  • status_code: number

HTTP status code.

format: int32

  • method: string

The MCP method that failed (for example initialize or tools/list).

  • refresh: BetaManagedAgentsRefreshObject or null

Details of the refresh-token exchange attempted on a 401. Null when no refresh was attempted.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response from the token endpoint. Populated only when status is failed.

  • status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"

Outcome of the refresh attempt.

  • "succeeded"

The token endpoint returned a new access token.

  • "failed"

The token endpoint returned an error response. See http_response for detail.

  • "connect_error"

The token endpoint could not be reached (DNS, TLS, or connection error).

  • "no_refresh_token"

No refresh token is stored for the credential, so no exchange was attempted.

  • status: BetaManagedAgentsCredentialValidationStatus

Overall verdict of the validation probe.

  • "valid"

The credential successfully authenticated against its MCP server.

  • "invalid"

The probe reached the MCP server and was rejected, and a refresh (if attempted) did not recover it.

  • "unknown"

The probe could not determine validity — for example, a transport error or a successful refresh that was not re-probed.

  • validated_at: string

When the validation probe was performed.

format: date-time

  • vault_id: string

Identifier of the vault containing the credential.

Beta Managed Agents Credential Validation Status

  • BetaManagedAgentsCredentialValidationStatus = "valid" or "invalid" or "unknown"

Overall verdict of a credential validation probe.

  • "valid"

The credential successfully authenticated against its MCP server.

  • "invalid"

The probe reached the MCP server and was rejected, and a refresh (if attempted) did not recover it.

  • "unknown"

The probe could not determine validity — for example, a transport error or a successful refresh that was not re-probed.

Beta Managed Agents Deleted Credential

  • BetaManagedAgentsDeletedCredential object

Confirmation of a deleted credential.

  • type: "vault_credential_deleted"
  • id: string

Unique identifier of the deleted credential.

Beta Managed Agents Environment Variable Auth Response

  • BetaManagedAgentsEnvironmentVariableAuthResponse object

Environment variable credential details. The secret value is never returned.

  • type: "environment_variable"
  • injection_location: BetaManagedAgentsInjectionLocationResponse

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

  • networking: BetaManagedAgentsUnrestrictedCredentialNetworkingResponse or BetaManagedAgentsLimitedCredentialNetworkingResponse

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

  • secret_name: string

Name of the environment variable.

Beta Managed Agents Environment Variable Create Params

  • BetaManagedAgentsEnvironmentVariableCreateParams object

Parameters for creating an environment variable credential.

  • type: "environment_variable"
  • networking: BetaManagedAgentsCredentialNetworkingParams

Outbound hosts the secret value is substituted on.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

  • secret_name: string

Name of the environment variable. Immutable after create.

minLength: 1, maxLength: 255

  • secret_value: string

Secret value. Write-only; never returned in responses.

minLength: 1, maxLength: 4096

  • injection_location: optional BetaManagedAgentsInjectionLocationParams

Where in the outbound request the secret value may be substituted.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

Beta Managed Agents Environment Variable Update Params

  • BetaManagedAgentsEnvironmentVariableUpdateParams object

Parameters for updating an environment variable credential. secret_name is immutable.

  • type: "environment_variable"
  • injection_location: optional BetaManagedAgentsInjectionLocationUpdateParams

Updated injection location.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

  • networking: optional BetaManagedAgentsCredentialNetworkingParams or null

Updated networking scope. Full replacement.

  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"
  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

  • secret_value: optional string or null

Updated secret value.

minLength: 1, maxLength: 4096

Beta Managed Agents Injection Location Params

  • BetaManagedAgentsInjectionLocationParams object

Where in the outbound request the secret value may be substituted.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

Beta Managed Agents Injection Location Response

  • BetaManagedAgentsInjectionLocationResponse object

Where in the outbound request the secret value is substituted.

  • body: boolean

Whether the placeholder is substituted in the request body.

  • header: boolean

Whether the placeholder is substituted in request header values.

Beta Managed Agents Injection Location Update Params

  • BetaManagedAgentsInjectionLocationUpdateParams object

Updated injection location.

  • body: optional boolean

Substitute when the placeholder appears in the request body.

  • header: optional boolean

Substitute when the placeholder appears in a request header value.

Beta Managed Agents Limited Credential Networking Params

  • BetaManagedAgentsLimitedCredentialNetworkingParams object

Substitute the secret only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. Each entry is a bare hostname (api.example.com), an IPv4 address (192.0.2.1), or a .-prefixed wildcard (.example.com). URLs, ports, paths, and IPv6 addresses are not accepted. At most 16 entries.

Beta Managed Agents Limited Credential Networking Response

  • BetaManagedAgentsLimitedCredentialNetworkingResponse object

The secret is substituted only on requests to the listed hosts.

  • type: "limited"
  • allowed_hosts: array of string

Hostnames on which the secret will be substituted. An entry matches the request host exactly; a *.-prefixed entry matches any subdomain of the named domain but not the domain itself.

Beta Managed Agents MCP OAuth Auth Response

  • BetaManagedAgentsMCPOAuthAuthResponse object

OAuth credential details for an MCP server.

  • type: "mcp_oauth"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshResponse or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

Beta Managed Agents MCP OAuth Create Params

  • BetaManagedAgentsMCPOAuthCreateParams object

Parameters for creating an MCP OAuth credential.

  • type: "mcp_oauth"
  • access_token: string

OAuth access token.

minLength: 1, maxLength: 8192

  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

minLength: 1, maxLength: 2047

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshParams or null

Refresh token configuration, if the credential supports token refresh.

  • client_id: string

OAuth client ID.

minLength: 1, maxLength: 1024

  • refresh_token: string

OAuth refresh token.

minLength: 1, maxLength: 8192

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

minLength: 1, maxLength: 2047

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam
  • BetaManagedAgentsTokenEndpointAuthNoneParam object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicParam object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostParam object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • resource: optional string or null

OAuth resource indicator.

minLength: 1, maxLength: 2047

  • scope: optional string or null

OAuth scope for the refresh request.

minLength: 1, maxLength: 8192

Beta Managed Agents MCP OAuth Refresh Params

  • BetaManagedAgentsMCPOAuthRefreshParams object

OAuth refresh token parameters for creating a credential with refresh support.

  • client_id: string

OAuth client ID.

minLength: 1, maxLength: 1024

  • refresh_token: string

OAuth refresh token.

minLength: 1, maxLength: 8192

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

minLength: 1, maxLength: 2047

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneParam or BetaManagedAgentsTokenEndpointAuthBasicParam or BetaManagedAgentsTokenEndpointAuthPostParam
  • BetaManagedAgentsTokenEndpointAuthNoneParam object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicParam object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostParam object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

  • resource: optional string or null

OAuth resource indicator.

minLength: 1, maxLength: 2047

  • scope: optional string or null

OAuth scope for the refresh request.

minLength: 1, maxLength: 8192

Beta Managed Agents MCP OAuth Refresh Response

  • BetaManagedAgentsMCPOAuthRefreshResponse object

OAuth refresh token configuration returned in credential responses.

  • client_id: string

OAuth client ID.

  • token_endpoint: string

Token endpoint URL used to refresh the access token.

  • token_endpoint_auth: BetaManagedAgentsTokenEndpointAuthNoneResponse or BetaManagedAgentsTokenEndpointAuthBasicResponse or BetaManagedAgentsTokenEndpointAuthPostResponse
  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"
  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • resource: optional string or null

OAuth resource indicator.

  • scope: optional string or null

OAuth scope for the refresh request.

Beta Managed Agents MCP OAuth Refresh Update Params

  • BetaManagedAgentsMCPOAuthRefreshUpdateParams object

Parameters for updating OAuth refresh token configuration.

  • refresh_token: optional string or null

Updated OAuth refresh token.

minLength: 1, maxLength: 8192

  • scope: optional string or null

Updated OAuth scope for the refresh request.

maxLength: 8192

  • token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam
  • BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object

Updated HTTP Basic authentication parameters for the token endpoint.

  • type: "client_secret_basic"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostUpdateParam object

Updated POST body authentication parameters for the token endpoint.

  • type: "client_secret_post"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents MCP OAuth Update Params

  • BetaManagedAgentsMCPOAuthUpdateParams object

Parameters for updating an MCP OAuth credential. The mcp_server_url is immutable.

  • type: "mcp_oauth"
  • access_token: optional string or null

Updated OAuth access token.

minLength: 1, maxLength: 8192

  • expires_at: optional string or null

A timestamp in RFC 3339 format

format: date-time

  • refresh: optional BetaManagedAgentsMCPOAuthRefreshUpdateParams or null

Updated refresh token configuration.

  • refresh_token: optional string or null

Updated OAuth refresh token.

minLength: 1, maxLength: 8192

  • scope: optional string or null

Updated OAuth scope for the refresh request.

maxLength: 8192

  • token_endpoint_auth: optional BetaManagedAgentsTokenEndpointAuthBasicUpdateParam or BetaManagedAgentsTokenEndpointAuthPostUpdateParam
  • BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object

Updated HTTP Basic authentication parameters for the token endpoint.

  • type: "client_secret_basic"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

  • BetaManagedAgentsTokenEndpointAuthPostUpdateParam object

Updated POST body authentication parameters for the token endpoint.

  • type: "client_secret_post"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents MCP Probe

  • BetaManagedAgentsMCPProbe object

The failing step of an MCP validation probe.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response. Null when no HTTP response was received (timeout, DNS, TLS).

  • body: string

Response body. May be truncated and has sensitive values scrubbed.

  • body_truncated: boolean

Whether body was truncated.

  • content_type: string

Value of the Content-Type response header.

  • status_code: number

HTTP status code.

format: int32

  • method: string

The MCP method that failed (for example initialize or tools/list).

Beta Managed Agents Refresh HTTP Response

  • BetaManagedAgentsRefreshHTTPResponse object

An HTTP response captured during a credential validation probe.

  • body: string

Response body. May be truncated and has sensitive values scrubbed.

  • body_truncated: boolean

Whether body was truncated.

  • content_type: string

Value of the Content-Type response header.

  • status_code: number

HTTP status code.

format: int32

Beta Managed Agents Refresh Object

  • BetaManagedAgentsRefreshObject object

Outcome of a refresh-token exchange attempted during credential validation.

  • http_response: BetaManagedAgentsRefreshHTTPResponse or null

The captured HTTP error response from the token endpoint. Populated only when status is failed.

  • body: string

Response body. May be truncated and has sensitive values scrubbed.

  • body_truncated: boolean

Whether body was truncated.

  • content_type: string

Value of the Content-Type response header.

  • status_code: number

HTTP status code.

format: int32

  • status: "succeeded" or "failed" or "connect_error" or "no_refresh_token"

Outcome of the refresh attempt.

  • "succeeded"

The token endpoint returned a new access token.

  • "failed"

The token endpoint returned an error response. See http_response for detail.

  • "connect_error"

The token endpoint could not be reached (DNS, TLS, or connection error).

  • "no_refresh_token"

No refresh token is stored for the credential, so no exchange was attempted.

Beta Managed Agents Static Bearer Auth Response

  • BetaManagedAgentsStaticBearerAuthResponse object

Static bearer token credential details for an MCP server.

  • type: "static_bearer"
  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

Beta Managed Agents Static Bearer Create Params

  • BetaManagedAgentsStaticBearerCreateParams object

Parameters for creating a static bearer token credential.

  • type: "static_bearer"
  • token: string

Static bearer token value.

minLength: 1, maxLength: 8192

  • mcp_server_url: string

URL of the MCP server this credential authenticates against.

minLength: 1, maxLength: 2047

Beta Managed Agents Static Bearer Update Params

  • BetaManagedAgentsStaticBearerUpdateParams object

Parameters for updating a static bearer token credential. The mcp_server_url is immutable.

  • type: "static_bearer"
  • token: optional string or null

Updated static bearer token value.

minLength: 1, maxLength: 8192

Beta Managed Agents Token Endpoint Auth Basic Param

  • BetaManagedAgentsTokenEndpointAuthBasicParam object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents Token Endpoint Auth Basic Response

  • BetaManagedAgentsTokenEndpointAuthBasicResponse object

Token endpoint uses HTTP Basic authentication with client credentials.

  • type: "client_secret_basic"

Beta Managed Agents Token Endpoint Auth Basic Update Param

  • BetaManagedAgentsTokenEndpointAuthBasicUpdateParam object

Updated HTTP Basic authentication parameters for the token endpoint.

  • type: "client_secret_basic"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents Token Endpoint Auth None Param

  • BetaManagedAgentsTokenEndpointAuthNoneParam object

Token endpoint requires no client authentication.

  • type: "none"

Beta Managed Agents Token Endpoint Auth None Response

  • BetaManagedAgentsTokenEndpointAuthNoneResponse object

Token endpoint requires no client authentication.

  • type: "none"

Beta Managed Agents Token Endpoint Auth Post Param

  • BetaManagedAgentsTokenEndpointAuthPostParam object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"
  • client_secret: string

OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents Token Endpoint Auth Post Response

  • BetaManagedAgentsTokenEndpointAuthPostResponse object

Token endpoint uses POST body authentication with client credentials.

  • type: "client_secret_post"

Beta Managed Agents Token Endpoint Auth Post Update Param

  • BetaManagedAgentsTokenEndpointAuthPostUpdateParam object

Updated POST body authentication parameters for the token endpoint.

  • type: "client_secret_post"
  • client_secret: optional string or null

Updated OAuth client secret.

minLength: 1, maxLength: 512

Beta Managed Agents Unrestricted Credential Networking Params

  • BetaManagedAgentsUnrestrictedCredentialNetworkingParams object

Substitute the secret on any host the session's Environment network policy permits egress to. The Environment's network policy is the only boundary on where the secret can reach.

  • type: "unrestricted"

Beta Managed Agents Unrestricted Credential Networking Response

  • BetaManagedAgentsUnrestrictedCredentialNetworkingResponse object

The secret is substituted on any host the session's Environment network policy permits egress to.

  • type: "unrestricted"
On this page
Create CredentialPath parametersHeadersBody parametersReturnsExampleResponse (200)List CredentialsPath parametersQuery parametersHeadersReturnsExampleResponse (200)Get CredentialPath parametersHeadersReturnsExampleResponse (200)Update CredentialPath parametersHeadersBody parametersReturnsExampleResponse (200)Delete CredentialPath parametersHeadersReturnsExampleResponse (200)Archive CredentialPath parametersHeadersReturnsExampleResponse (200)Validate CredentialPath parametersHeadersReturnsExampleResponse (200)Domain typesBeta Managed Agents CredentialBeta Managed Agents Credential Networking ParamsBeta Managed Agents Credential ValidationBeta Managed Agents Credential Validation StatusBeta Managed Agents Deleted CredentialBeta Managed Agents Environment Variable Auth ResponseBeta Managed Agents Environment Variable Create ParamsBeta Managed Agents Environment Variable Update ParamsBeta Managed Agents Injection Location ParamsBeta Managed Agents Injection Location ResponseBeta Managed Agents Injection Location Update ParamsBeta Managed Agents Limited Credential Networking ParamsBeta Managed Agents Limited Credential Networking ResponseBeta Managed Agents MCP OAuth Auth ResponseBeta Managed Agents MCP OAuth Create ParamsBeta Managed Agents MCP OAuth Refresh ParamsBeta Managed Agents MCP OAuth Refresh ResponseBeta Managed Agents MCP OAuth Refresh Update ParamsBeta Managed Agents MCP OAuth Update ParamsBeta Managed Agents MCP ProbeBeta Managed Agents Refresh HTTP ResponseBeta Managed Agents Refresh ObjectBeta Managed Agents Static Bearer Auth ResponseBeta Managed Agents Static Bearer Create ParamsBeta Managed Agents Static Bearer Update ParamsBeta Managed Agents Token Endpoint Auth Basic ParamBeta Managed Agents Token Endpoint Auth Basic ResponseBeta Managed Agents Token Endpoint Auth Basic Update ParamBeta Managed Agents Token Endpoint Auth None ParamBeta Managed Agents Token Endpoint Auth None ResponseBeta Managed Agents Token Endpoint Auth Post ParamBeta Managed Agents Token Endpoint Auth Post ResponseBeta Managed Agents Token Endpoint Auth Post Update ParamBeta Managed Agents Unrestricted Credential Networking ParamsBeta Managed Agents Unrestricted Credential Networking Response