Skip to main content
Credentials

Credential Schemas

Forward API reference.

Vault credential object

Create, update, get, list, and archive endpoints return this structure. Credential secrets such as token, access_token, refresh_token, client_secret, and secret_value are accepted only in create or update requests and are never returned in responses.
FieldTypeDescription
idstringCredential ID with the vcred_ prefix
typestringAlways "vault_credential"
vault_idstringOwning Vault ID
authCredential auth objectSanitized auth details; secrets are never returned
display_namestringCompatibility field. Currently always an empty string and not persisted
metadataobjectCustom metadata object stored with the credential; defaults to {}
archived_atstring | nullArchive time in RFC 3339 format; null while active
created_atstringCreation time in RFC 3339 format
updated_atstringLast update time in RFC 3339 format

Identity ownership

An account (or Workspace) can have multiple Identities. Each Identity represents an end user of the product integrated with that account (or Workspace). A Credential does not store ownership separately. It inherits ownership entirely from its Vault:
  • Before accessing a Credential, the service checks its Vault against the current ownership scope. In a valid Identity scope, a Vault owned by another Identity returns 404. PAT calls without identity_id and Admin SAT calls retain the existing Owner mismatch 403. If this check fails, Credential processing does not continue.
  • Every Credential in an Identity-owned Vault is visible only to that Identity.
  • Create, list, get, update, archive, and delete Credential endpoints support the identity_id query parameter with the same semantics as Vaults. See Vault identity ownership.
identity_id is optional and is used only for Identity-owned resources. A PAT can specify it explicitly; omitting it uses the administrator scope. With SAT, issue an Identity-scoped token and do not explicitly pass this parameter; otherwise, the request returns HTTP 400.

Create credential request

FieldTypeRequiredDescription
authCredential auth objectYesCredential authentication information
metadataobjectNoCustom metadata stored with the credential; defaults to {}

Update credential request

Only auth and metadata are accepted, and at least one field is required. Other fields return 400 invalid_request_error.
FieldTypeRequiredDescription
authobjectNoPartially updates authentication information. It must include a type that matches the current Credential type
metadataobject | nullNoMerge patch. A null value in the object removes that key; top-level null clears all metadata
See Update a Credential for the complete field constraints.

Credential auth object

auth uses type to select the authentication type. Responses never include secret fields.

static_bearer

FieldTypeRequiredDescription
typestringYesAlways "static_bearer"
mcp_server_urlstringYesMCP server URL, at most 2048 characters
tokenstringYes (request)Static Bearer token. Accepted only in create requests and never returned in responses

mcp_oauth

FieldTypeRequiredDescription
typestringYesAlways "mcp_oauth"
mcp_server_urlstringYesMCP server URL, at most 2048 characters
client_idstringYesOAuth client ID
client_secretstringYes (request)OAuth client secret. Accepted only in create requests and never returned in responses
access_tokenstringNo (request)Access token already obtained through OAuth. Accepted only in create requests and never returned in responses
refresh_tokenstringNo (request)OAuth refresh token. Accepted only in create requests and never returned in responses

environment_variable

FieldTypeRequiredDescription
typestringYesAlways "environment_variable"
secret_namestringYes (create request)Environment variable name. Must match [A-Za-z_][A-Za-z0-9_]* and cannot be changed after creation
secret_valuestringYes (create request)Environment variable value. Accepted in create or update requests and never returned in responses
injection_locationobjectNoInjection location configuration. It can contain the boolean fields body and header
networkingobjectNoNetwork access constraint. Supports unrestricted or limited with allowed_hosts
The create endpoint for the Forward Credential API defines the supported authentication types. Unlisted types return 400 invalid_request_error during creation.

List pagination fields

FieldTypeDescription
dataarray of Vault credential objectsRecords on the current page
has_morebooleanWhether another page is available
next_pagestring | nullForward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null
first_idstring | nullID of the first record on the current page
last_idstring | nullID of the last record on the current page
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.