API reference · Credential broker
Store a credential agents can use without seeing it
POST /fabric/broker/credentials
Last reviewed 2026-10-02
POST /fabric/broker/credentials
Request body
CredentialRequest (required)
| Field | Type | Meaning |
|---|---|---|
name required | string | min length 1 · max length 63 |
kind | string | bearer, header, basic (user:password) or query default "bearer" |
secret required | string | min length 1 · max length 8192 |
allowed_hosts required | array of string | min items 1 · max items 20 |
allowed_methods | array of string | |
header_name | string or null | max length 64 |
description | string or null | max length 200 |
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | JSON |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X POST 'https://cainstudio.online/fabric/broker/credentials' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"name": "name", "kind": "bearer", "secret": "secret", "allowed_hosts": ["allowed-hosts"]}'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/broker/credentials', method='POST',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps({
"name": "name",
"kind": "bearer",
"secret": "secret",
"allowed_hosts": [
"allowed-hosts"
]
}).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/broker/credentials", {
method: "POST",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify({
"name": "name",
"kind": "bearer",
"secret": "secret",
"allowed_hosts": [
"allowed-hosts"
]
}),
});
console.log(res.status, await res.json());Schemas used
CredentialRequest · HTTPValidationError · ValidationError
← Brokered credentials (the secrets are never returned) · all 4 Credential broker calls · Revoke a brokered credential →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem