Skip to main content
Version: 2026.09

Credentials

Store a secret the platform can hand to a job, complete a browser link against an auth integration, or create an org-owned service connection. The sealed secret is not returned on StoredCredential. Status values are CredentialStatus: active, revoked, expired.

Jobs that need a stored credential pass it as auth_bindings on add_job(). See Connected resources.

All methods are on the Client.

Stored secrets​

list_credentials()​

Lists credentials visible to the caller. The secret value is not included.

  • Parameters:

    • auth_integration_id (str, optional) – Only credentials for this auth integration.
    • http_request_timeout_secs (int, optional)
  • Return Type: list of StoredCredential

create_credential()​

Stores a credential from a secret you supply. The platform seals secret_value; it is absent from the returned object.

  • Parameters:

    • new_stored_credential (NewStoredCredential) – (required). name, auth_type (FunctionAuthType), and secret_value are required. Optional: auth_integration_id, account_identity, org_owned.
    • http_request_timeout_secs (int, optional)
  • Return Type: StoredCredential

update_credential()​

Renames a stored credential. This call changes the label only.

  • Parameters:

    • credential_id (str) – Credential to update. (required)
    • credential_update (CredentialUpdate) – (required). name.
    • http_request_timeout_secs (int, optional)
  • Return Type: StoredCredential

delete_credential()​

Disconnects a credential.

  • Parameters:

    • credential_id (str) – Credential to delete. (required)
    • http_request_timeout_secs (int, optional)
  • Return Type: None

validate_credential()​

Probes whether a stored credential is still live.

  • Parameters:

    • credential_id (str) – Credential to probe. (required)
    • http_request_timeout_secs (int, optional)
  • Return Type: CredentialValidation

get_credential_authorize_url()​

Builds the provider URL that starts a browser link.

  • Parameters:

    • auth_integration_id (str) – Auth integration to link against. (required)
    • redirect_uri (str) – Where the provider returns the browser. (required)
    • http_request_timeout_secs (int, optional)
  • Return Type: AuthorizeUrl — includes the opaque handle that link_credential() expects.

Completes a browser link after the provider redirects back.

  • Parameters:

    • new_credential_link (NewCredentialLink) – (required). handle is the session id from AuthorizeUrl. code and state are the values the provider returned. Optional: name, org_owned, reconnect_credential_id.
    • http_request_timeout_secs (int, optional)
  • Return Type: StoredCredential

create_service_connection()​

Creates an org-owned service connection with no browser authorization. For OAuth 1.0a two-legged mode, requests sign with the integration's consumer key and secret and act as the service identity.

  • Parameters:

    • new_service_connection (NewServiceConnection) – (required). auth_integration_id is required. name is optional.
    • http_request_timeout_secs (int, optional)
  • Return Type: StoredCredential

Control tags​

get_credential_control_taggings()​

Returns the control tags currently on a credential.

  • Parameters:

    • credential_id (str) – (required)
    • http_request_timeout_secs (int, optional)
  • Return Type: list of StoredCredentialControlTagging

get_credential_control_tagging_history()​

Returns the control-tag history for a credential.

  • Parameters:

    • credential_id (str) – (required)
    • http_request_timeout_secs (int, optional)
  • Return Type: list of StoredCredentialControlTagging

patch_credential_control_taggings()​

Adds or removes control tags on a credential.

  • Parameters:

    • credential_id (str) – (required)
    • request_body (list of str) – Control tag ids. (required)
    • patch_op (PatchOp) – set or delete. The parameter description marks this required even though the client defaults it to None.
    • reason (str, optional)
    • http_request_timeout_secs (int, optional)
  • Return Type: list of StoredCredentialControlTagging

StoredCredential​

A named credential held for a user or an org. owner_user_id is null for an org-owned credential. Fields: id, created, created_by_id, name, auth_type, status, tenant_id, owner_user_id, auth_integration_id, account_identity, control_tags.