Skip to main content
POST
Create a credential

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json

Request to create a new credential

domain
string
required

Target domain this credential is for

Example:

"netflix.com"

name
string
required

Unique name for the credential within the project

Example:

"my-netflix-login"

values
object
required

Field name to value mapping (e.g., username, password)

Example:
sso_provider
string

If set, indicates this credential should be used with the specified SSO provider (e.g., google, github, microsoft). When the target site has a matching SSO button, it will be clicked first before filling credential values on the identity provider's login page.

Example:

"google"

totp_algorithm
enum<string>

HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when an otpauth:// URI supplies the algorithm.

Available options:
SHA1,
SHA256,
SHA512
Example:

"SHA1"

totp_digits
integer

Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an otpauth:// URI supplies the digit count.

Required range: 6 <= x <= 9
Example:

6

totp_period
integer

TOTP rotation period in seconds. Defaults to 30 and is ignored when an otpauth:// URI supplies the period.

Required range: 15 <= x <= 300
Example:

30

totp_secret
string

Accepts a 16-128 character base32-encoded TOTP secret or an otpauth://totp/... URI. The range accepts existing shorter seeds and longer seeds regardless of HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for SHA1/SHA256/SHA512. Only URI parameters present override the corresponding explicit TOTP fields. Used for automatic 2FA during login.

Example:

"JBSWY3DPEHPK3PXP"

Response

Credential created successfully

A stored credential for automatic re-authentication

created_at
string<date-time>
required

When the credential was created

Example:

"2025-01-15T10:30:00Z"

domain
string
required

Target domain this credential is for

Example:

"netflix.com"

id
string
required

Unique identifier for the credential

Example:

"cred_abc123xyz"

name
string
required

Unique name for the credential within the project

Example:

"my-netflix-login"

updated_at
string<date-time>
required

When the credential was last updated

Example:

"2025-01-15T10:30:00Z"

has_totp_secret
boolean

Whether this credential has a TOTP secret configured for automatic 2FA

Example:

false

has_values
boolean

Whether this credential has stored values (email, password, etc.)

Example:

true

sso_provider
string | null

If set, indicates this credential should be used with the specified SSO provider (e.g., google, github, microsoft). When the target site has a matching SSO button, it will be clicked first before filling credential values on the identity provider's login page.

Example:

"google"

totp_algorithm
enum<string>

HMAC algorithm used to generate TOTP codes. Defaults to SHA1 for credentials created before this metadata was stored.

Available options:
SHA1,
SHA256,
SHA512
Example:

"SHA1"

totp_code
string

Current TOTP code. Only included in create/update responses when totp_secret was just set.

Example:

"847291"

totp_code_expires_at
string<date-time>

When the totp_code expires. Only included when totp_code is present.

Example:

"2025-01-15T10:30:30Z"

totp_digits
integer

Number of digits in generated TOTP codes. Defaults to 6 for credentials created before this metadata was stored.

Required range: 6 <= x <= 9
Example:

6

totp_period
integer

TOTP rotation period in seconds. Defaults to 30 for credentials created before this metadata was stored.

Required range: 15 <= x <= 300
Example:

30

value_keys
string[]

The field names stored in this credential's values (e.g., username, password). Values themselves are never returned. Included on single-credential responses (create, get by id or name, update); omitted from list responses.

Example: