コンテンツにスキップ

list_credentials

GET
/api/v1/credentials
curl --request GET \
--url https://example.com/api/v1/credentials \
--header 'Authorization: Bearer <token>'

Credential metadata only — the secret is never returned

Media typeapplication/json
Array<object>

Credential metadata returned by the API — never includes the secret value.

object
id
required
string format: uuid
kind
required
string
name
required
string
used_by
required

How many nodes reference this credential. Counted at list time from nodes.credential_id. Deleting the credential clears those bindings (ON DELETE SET NULL).

⚠️ Nodes only, and the name predates the two fields below: 0 here used to read as “unused” for a Meraki key that three organizations were being polled with.

integer format: int64
used_by_meraki_orgs
required

How many Meraki organizations are polled with it (ADR-164 Inc.6).

🚨 Not a binding that can be cleared: meraki_orgs.credential_id is NOT NULL … ON DELETE RESTRICT, so while this is above zero the delete is refused with 409 credential_in_use.

integer format: int64
used_by_netbox_servers
required

How many NetBox servers are read with it. Refuses the delete exactly as the field above does (netbox_servers.credential_id, the same constraint).

integer format: int64
Examplegenerated
[
{
"id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"kind": "example",
"name": "example",
"used_by": 1,
"used_by_meraki_orgs": 1,
"used_by_netbox_servers": 1
}
]

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role does not hold ManageCredentials

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Skeleton mode has no write side

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}