API referenceKeys and access
List vendor credentials
Your own vendor keys (BYOK) stored for this org: provider, slot, label, field names, the key's last four characters and its last test result. Secrets are write-only and never returned.
Authorization
bearer AuthorizationBearer <token>
In: header
Response Body
application/json
application/json
curl -X GET "https://example.com/v1/credentials"{ "items": [ { "object": "credential", "id": "string", "provider": "string", "slot": "primary", "fields": [ "string" ], "label": null, "hint": null, "status": "healthy", "tested_at": null, "test_message": null, "last_used_at": null, "updated_at": "2019-08-24T14:15:22Z" } ], "providers": [ { "slug": "string", "name": "string", "fields": [ "string" ], "testable": true, "sandbox": true, "auth": "header", "auth_field": "api_key", "auth_name": null, "rapidapi_host": null, "key_url": null, "key_help": null, "supply": [ "byok" ] } ]}Exchange an app code for a key POST
Final step of Sign in with GridRouter: exchange the one-time code and its PKCE code_verifier for a user-controlled key with call/run scopes and any credit limit the user set.
Add a vendor credential PUT
Store your own key for a provider as the primary or fallback slot, envelope-encrypted. BYOK calls are never charged by GridRouter.