Credentials
Encrypted connection credential drafts, isolated validation, and metadata-only reads.
Operations
Each operation lists its specific responses. See Common error responses for errors shared by every operation on this page.
List connection credential draft metadata
GET /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts
Operation ID: listConnectionCredentialDrafts
Effect: read
Confirmation: never
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
project |
path | Yes | string | |
target |
path | Yes | string | |
connection |
path | Yes | string | |
limit |
query | No | integer | |
beforeVersionId |
query | No | string |
Responses
| Status | Description |
|---|---|
200 |
The request has succeeded. |
Save a connection credential draft
POST /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts
Stores a new encrypted, immutable draft only. Saving does not validate, publish or activate the credential. A lost response can leave an unreturned draft; explicit resubmission may create a second draft.
Operation ID: saveCredentialDraft
Effect: write
Confirmation: conditional
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
project |
path | Yes | string | |
target |
path | Yes | string | |
connection |
path | Yes | string |
Request body
Content types: application/json.
Responses
| Status | Description |
|---|---|
201 |
The request has succeeded and a new resource has been created as a result. |
Read connection credential draft metadata
GET /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts/{version}
Operation ID: getConnectionCredentialDraft
Effect: read
Confirmation: never
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
project |
path | Yes | string | |
target |
path | Yes | string | |
connection |
path | Yes | string | |
version |
path | Yes | string |
Responses
| Status | Description |
|---|---|
200 |
The request has succeeded. |
Validate a saved connection credential draft
POST /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts/{version}/validate
Requires both connection.manage and connection.use on the exact connection. Probes only the saved PostgreSQL password version against the server-owned binding at expectedBindingRevision; it never changes running pools. Every explicit submission performs a fresh probe; Idempotency-Key is forbidden. A lost response may leave a receipt without returning it. Success means validated, not in use.
Operation ID: validateCredentialDraft
Effect: write
Confirmation: conditional
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
project |
path | Yes | string | |
target |
path | Yes | string | |
connection |
path | Yes | string | |
version |
path | Yes | string |
Request body
Content types: application/json.
Responses
| Status | Description |
|---|---|
200 |
The request has succeeded. |
Common error responses
These error responses apply to every operation on this page.
| Status | Description |
|---|---|
400 |
The server could not understand the request due to invalid syntax. |
401 |
Access is unauthorized. |
403 |
Access is forbidden. |
404 |
The server cannot find the requested resource. |
409 |
The request conflicts with the current state of the server. |
412 |
Precondition failed. |
413 |
Client error |
415 |
Client error |
422 |
Client error |
429 |
Client error |
500 |
Server error |
502 |
Server error |
503 |
Service unavailable. |