Retrieve the current credential
/credentials/currentReturns the credential used to authenticate the request, reflecting its current state. Available to any authenticated credential without additional permissions.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Response Body
application/json
application/json
curl -X GET "https://example.com/credentials/current"{ "data": { "auth_mode": "autonomous", "created_at": "2019-08-24T14:15:22Z", "created_by": { "id": "string", "kind": "admin" }, "environment": "production", "expires_at": "2019-08-24T14:15:22Z", "human": { "admin_id": "string", "eligible_since": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z" }, "id": "string", "name": "string", "object": "credential", "policy": { "active_version": 0, "auth_revision": 0 }, "purpose": "string", "revision": 0, "revoked_at": "2019-08-24T14:15:22Z", "revoked_by": { "id": "string", "kind": "admin" }, "secret": { "configured": true, "issued_at": "2019-08-24T14:15:22Z", "last4": "string", "rotated_at": "2019-08-24T14:15:22Z", "valid_until": "2019-08-24T14:15:22Z", "value": "string", "version": 0 }, "status": "active", "updated_at": "2019-08-24T14:15:22Z" }}Create a credential POST
Issues a new API credential for the current account and, optionally, its initial access policies. Each entry in `policies` specifies either a list of `capabilities` or a policy `template`, together with the `resources` it applies to. Available templates are returned by the list policy templates operation. The credential secret is returned only in this response and cannot be retrieved again. Store it securely. The new credential cannot receive permissions beyond those the calling credential is allowed to delegate. Such requests are rejected with `delegation_limit_exceeded` and no credential is issued.
Retrieve the current credential's policies GET
Returns the active policy revision of the credential used to authenticate the request. Use this operation to inspect what the calling credential is allowed to do; it cannot be used to read other credentials.