CAIN-42 CAIN Studio

API reference · Credential broker

Store a credential agents can use without seeing it

POST /fabric/broker/credentials

Last reviewed 2026-10-02

POST /fabric/broker/credentials

Request body

CredentialRequest (required)

FieldTypeMeaning
name requiredstringmin length 1 · max length 63
kindstringbearer, header, basic (user:password) or query
default "bearer"
secret requiredstringmin length 1 · max length 8192
allowed_hosts requiredarray of stringmin items 1 · max items 20
allowed_methodsarray of string
header_namestring or nullmax length 64
descriptionstring or nullmax length 200

Responses

StatusMeaningBody
200Successful ResponseJSON
422Validation ErrorHTTPValidationError
401No key, or a key that is not validJSON detail
429Rate limit for your plan reached; retry after the Retry-After secondsJSON detail

Try it

This call changes data in the account the key belongs to.

The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.

Code

curl -sS -X POST 'https://cainstudio.online/fabric/broker/credentials' \
  -H "X-API-Key: $CAIN_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"name": "name", "kind": "bearer", "secret": "secret", "allowed_hosts": ["allowed-hosts"]}'

Schemas used

CredentialRequest · HTTPValidationError · ValidationError

← Brokered credentials (the secrets are never returned) · all 4 Credential broker calls · Revoke a brokered credential →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem