---
title: "List Credentials"
method: GET
path: "/v1/vaults/{vault_id}/credentials?beta=true"
---

# List Credentials

`GET /v1/vaults/{vault_id}/credentials?beta=true`

## Path parameters

- `vault_id` string, required

## Query parameters

- `limit` integer
- `page` string
- `include_archived` boolean

## Headers

- `x-api-key` string
- `anthropic-version` string
- `anthropic-beta` string

## Response `200`

Successful response (OK)

- BetaManagedAgentsListCredentialsResponse — Response containing a paginated list of credentials.
  - `data` BetaManagedAgentsCredential[] — List of credentials.
    - `type` 'vault_credential', required
    - `id` string, required — Unique identifier for the credential.
    - `vault_id` string, required — Identifier of the vault this credential belongs to.
    - `display_name` string, nullable — Human-readable name for the credential.
    - `metadata` object, required — Arbitrary key-value metadata attached to the credential.
    - `created_at` string, date-time, required — A timestamp in RFC 3339 format
    - `updated_at` string, date-time, required — A timestamp in RFC 3339 format
    - `archived_at` string, date-time, required — A timestamp in RFC 3339 format
    - `auth` union, required — Authentication details for a credential.
      - object — OAuth credential details for an MCP server.
        - `type` 'mcp_oauth', required
        - `mcp_server_url` string, required — URL of the MCP server this credential authenticates against.
        - `expires_at` string, date-time — A timestamp in RFC 3339 format
        - `refresh` BetaManagedAgentsMcpOauthRefreshResponse — OAuth refresh token configuration returned in credential responses.
          - `token_endpoint` string, required — Token endpoint URL used to refresh the access token.
          - `client_id` string, required — OAuth client ID.
          - `resource` string, nullable — OAuth resource indicator.
          - `scope` string, nullable — OAuth scope for the refresh request.
          - `token_endpoint_auth` union, required
            - object — Token endpoint requires no client authentication.
              - …
            - object — Token endpoint uses HTTP Basic authentication with client credentials.
              - …
            - object — Token endpoint uses POST body authentication with client credentials.
              - …
      - object — Static bearer token credential details for an MCP server.
        - `type` 'static_bearer', required
        - `mcp_server_url` string, required — URL of the MCP server this credential authenticates against.
      - object — Environment variable credential details. The secret value is never returned.
        - `type` 'environment_variable', required
        - `secret_name` string, required — Name of the environment variable.
        - `networking` union, required
          - object — The secret is substituted on any host the session's Environment network policy permits egress to.
            - `type` 'unrestricted', required
          - object — The secret is substituted only on requests to the listed hosts.
            - `type` 'limited', required
            - `allowed_hosts` string[], required — Hostnames on which the secret will be substituted. An entry matches the request host exactly; a `*.`-prefixed entry matches any subdomain of the named domain but not the domain itself.
        - `injection_location` BetaManagedAgentsInjectionLocationResponse, required — Where in the outbound request the secret value is substituted.
          - `header` boolean, required — Whether the placeholder is substituted in request header values.
          - `body` boolean, required — Whether the placeholder is substituted in the request body.
  - `next_page` string, nullable — Pagination token for the next page, or null if no more results.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time

---

[API](https://skmtc.net/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.net/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/anthropics/anthropic-api/versions/93d8fd7d6493/schema)
