Skip to navigation

Get a credential

Serves one credential of the organisation — references and metadata, never the key material; any other id is 404.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

idintegerRequired

The record's id — a positive 32-bit integer the platform minted.

Query parameters

viewenumOptionalDefaults to latest

latest (the default) shows a row's pending proposal where one exists; approved shows what the platform enforces. Resources without proposals serve the same rows for both.

Allowed values:

Response

The credential's row, rendered as the guide's Reads section describes: the position header and body field, the ETag, money as decimal strings.

credentialIdinteger
Sticky entity key.
globalSequencestringformat: "^[0-9]+$"

The position as a decimal string — the last change this member had applied, orders and balance readings included.

keyFingerprintstring

The credential's fingerprint as the intake computed it — fp- and the first 16 hex characters of SHA-256 over the canonical payload — the pin a connector adopts the material at: enough to prove a cutover, never enough to sign. Empty on a row seeded before the intake.

namestring

Natural key — per-org unique among live credentials.

orgIdinteger

Owner-stamped.

pendingTransitionenum

ACTIVATE, AMEND (capabilities/secretRef), REACTIVATE, REVOKE or ROTATE; NONE otherwise. NONE is the unset sentinel: outputs only — as input, omit the field instead; explicit NONE refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as NONE, never as an error; as input an unknown name refuses 400 — the parse is strict

providerKindenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

secretRefstring

LOGICAL credential name (okx-account-prod) — never a store path or provider URI; resolution happens only at the owning connector's edge.

statusenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

venueKeyIdstring

The venue's identifier for the key — metadata, not material.

versionstringformat: "^-?[0-9]+$"
Monotonic per entity. int64 as a decimal JSON string
allowlistDetailstringOptional

The venue's own allowlist, verbatim (IP addresses are not secrets); empty when none or no probe answered.

appGroupstringOptional

The connector app group serving this credential (desk 5-as-amended, okx-oe D-E17): the assignment rides the row — one group per credential by construction, empty = unassigned (no connector serves it; fail-safe). Replaces the compile-time CredentialAssignments table.

canExecuteTransfersbooleanOptional

Whether the key may execute transfers. a boolean; absent reads false

canReadBalancesbooleanOptional

Whether the key may read balances. a boolean; absent reads false

canServeAddressesbooleanOptional

Whether the key may serve deposit addresses. a boolean; absent reads false

canTradebooleanOptional

Capability boolean: an order routes through its account's trading pipe — the account's designated tradingCredentialId, else its own credential — which must be ACTIVE and carry canTrade. Any number of trading credentials may share one (org × venue) — one venue key per sub-account. a boolean; absent reads false

exchangeIdinteger or nullOptional

The refdata exchange for an EXCHANGE-kind credential — carried, not resolved here; a credential that can trade must name one (MISSING_VENUE); 0 = no venue.

keyCreatedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

Key metadata: when the venue key was minted; 0 = not stated. int64 as a decimal JSON string

observedAllowlistenumOptional

The probe's allowlist verdict against the cluster's egress set; UNKNOWN until a probe answers. UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
observedKeyCreatedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

The key creation time the venue stated to the probe; 0 = the venue states none, or never probed. int64 as a decimal JSON string

observedKeyFingerprintstringOptional

The fingerprint of the material the probe adopted — compare with keyFingerprint, the intake's pin; empty until a probe answers.

observedKeyIdstringOptional

The venue-facing key identifier the probing connector resolved (the public half, never the secret); empty until a probe answers.

observedPermissionslist of enumsOptional

The observed axis: the key scopes the venue stated to the probing connector, parsed by name; empty until a probe answers. a set (SBE bit-set) served as the array of its set choice names in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict

Allowed values:
pendingByUserIdinteger or nullOptional

The user whose proposal is pending, so an approver is checked to be someone else; 0 when nothing is pending.

permissionDetailstringOptional

The venue's own permission string, verbatim (not a secret); empty until a probe answers.

probeDetailstringOptional

Redacted diagnostic text for a non-NONE probe outcome; empty-not-null.

probeOutcomeenumOptional

UNKNOWN = never probed; NONE = the venue's key-restrictions read answered; else the probe's own failure in the credential or gate band. UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

probedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

Consensus time of the probe report this row records — owner-stamped; 0 = never probed. int64 as a decimal JSON string

rotateByNsstring or nullOptionalformat: "^-?[0-9]+$"

Governance deadline for rotation; a breach is an ops alert; 0 = none. int64 as a decimal JSON string

venueAccountRefstringOptional

The venue's account identifier behind the key (OKX uid); empty when the venue states none or no probe answered.

unscaledbooleanOptionalDeprecated

Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.

Errors

400
Get Credentials Request Bad Request Error
401
Get Credentials Request Unauthorized Error
403
Get Credentials Request Forbidden Error
404
Get Credentials Request Not Found Error
503
Get Credentials Request Service Unavailable Error