Credentials

Encrypted connection credential drafts, isolated validation, and metadata-only reads.

Operations

Each operation lists its specific responses. See Common error responses for errors shared by every operation on this page.

List connection credential draft metadata

GET /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts

Operation ID: listConnectionCredentialDrafts
Effect: read
Confirmation: never
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown

Parameters

Name In Required Type Description
project path Yes string
target path Yes string
connection path Yes string
limit query No integer
beforeVersionId query No string

Responses

Status Description
200 The request has succeeded.

Save a connection credential draft

POST /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts

Stores a new encrypted, immutable draft only. Saving does not validate, publish or activate the credential. A lost response can leave an unreturned draft; explicit resubmission may create a second draft.

Operation ID: saveCredentialDraft
Effect: write
Confirmation: conditional
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown

Parameters

Name In Required Type Description
project path Yes string
target path Yes string
connection path Yes string

Request body

Content types: application/json.

Responses

Status Description
201 The request has succeeded and a new resource has been created as a result.

Read connection credential draft metadata

GET /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts/{version}

Operation ID: getConnectionCredentialDraft
Effect: read
Confirmation: never
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown

Parameters

Name In Required Type Description
project path Yes string
target path Yes string
connection path Yes string
version path Yes string

Responses

Status Description
200 The request has succeeded.

Validate a saved connection credential draft

POST /api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts/{version}/validate

Requires both connection.manage and connection.use on the exact connection. Probes only the saved PostgreSQL password version against the server-owned binding at expectedBindingRevision; it never changes running pools. Every explicit submission performs a fresh probe; Idempotency-Key is forbidden. A lost response may leave a receipt without returning it. Success means validated, not in use.

Operation ID: validateCredentialDraft
Effect: write
Confirmation: conditional
Required privilege: RESOURCE_MANAGE
Focused reference: JSON · Markdown

Parameters

Name In Required Type Description
project path Yes string
target path Yes string
connection path Yes string
version path Yes string

Request body

Content types: application/json.

Responses

Status Description
200 The request has succeeded.

Common error responses

These error responses apply to every operation on this page.

Status Description
400 The server could not understand the request due to invalid syntax.
401 Access is unauthorized.
403 Access is forbidden.
404 The server cannot find the requested resource.
409 The request conflicts with the current state of the server.
412 Precondition failed.
413 Client error
415 Client error
422 Client error
429 Client error
500 Server error
502 Server error
503 Service unavailable.