All Products
Search
Document Center

Identity as a Service:CreateUserExclusiveCredential

Last Updated:Aug 13, 2026

Creates an account-specific credential.

Operation description

This API uses an Access Token issued by IDaaS for identity authentication and authorization.

Ensure that the Access Token you pass in has the "Manage Static Credentials" permission for the IDaaS built-in PAM application (Privileged Access Management).

Note

The corresponding scope is urn:cloud:idaas:pam|credential:manage.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request syntax

POST /v2/{instanceId}/credentials/_/actions/createUserExclusive HTTP/1.1

Path Parameters

Parameter

Type

Required

Description

Example

instanceId

string

Yes

The EIAM instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

Request parameters

Parameter

Type

Required

Description

Example

Authorization

string

Yes

The authentication information. Format: Bearer ${access_token}.

Note

Enter the Access Token issued by IDaaS.

Bearer xxxxxx

body

object

No

The request body.

credentialIdentifier

string

Yes

The credential identifier.

credential_identifier_test

credentialName

string

Yes

The credential name.

credential_name

credentialScenarioLabel

string

No

The scenarios label of the credential. Valid values:

  • llm: large language model.

  • saas: third-party SaaS service.

llm

credentialType

string

Yes

The credential type. Valid values:

  • api_key: API Key authentication credential.

  • oauth_client: OAuth client authentication credential.

api_key

credentialContent

object

Yes

The credential content.

apiKeyContent

object

No

The credential content for the API Key credential type.

apiKey

string

Yes

The value of the API Key.

sk-nsklncmwizncxxxx

description

string

No

The credential description.

credential_description

credentialExternalId

string

No

The external unique identifier of the credential.

YNWLVQAZMNRROYWKxxx

returnCiphertext

boolean

No

Specifies whether to return the encrypted ciphertext of the credential.

true

Response elements

Element

Type

Description

Example

object

The response body.

credentialId

string

The credential ID.

cred_mkv7rgt4d7i4u7zqtzev2mxxxx

credentialIdentifier

string

The credential identifier.

credential_identifier_test

credentialCiphertext

string

The encrypted ciphertext of the credential.

eyJraWQiOiJBVVRIU0tFWxxxxx

Examples

Success response

JSON format

{
  "credentialId": "cred_mkv7rgt4d7i4u7zqtzev2mxxxx",
  "credentialIdentifier": "credential_identifier_test",
  "credentialCiphertext": "eyJraWQiOiJBVVRIU0tFWxxxxx"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.