All Products
Search
Document Center

Identity as a Service:ObtainCredential

Last Updated:Aug 13, 2026

Queries credential information and retrieves the credential plaintext.

Operation description

This API uses an Access Token issued by IDaaS for identity authentication and authorization.

Ensure that the Access Token you pass in has the "Obtain Static Credential" permission for the IDaaS built-in PAM application (Privileged Access Management).

Note

The corresponding scope is urn:cloud:idaas:pam|credential:obtain.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request syntax

GET /v2/{instanceId}/credentials/_/actions/obtain HTTP/1.1

Path Parameters

Parameter

Type

Required

Description

Example

instanceId

string

Yes

The EIAM instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

Request parameters

Parameter

Type

Required

Description

Example

Authorization

string

Yes

The authentication information. Format: Bearer ${access_token}.

Note

Enter the Access Token issued by IDaaS.

Bearer xxxxxx

credentialIdentifier

string

Yes

The credential identifier.

credential_identifier_test

Response elements

Element

Type

Description

Example

object

instanceId

string

The EIAM instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

credentialId

string

The credential ID.

cred_mkv7rgt4d7i4u7zqtzev2mxxxx

status

string

The credential status. Valid values:

  • enabled: Enabled.

  • disabled: Disabled.

enabled

credentialIdentifier

string

The credential identifier.

credential_identifier_test

credentialName

string

The credential name.

credential_name

credentialSubjectType

string

The subject type that the credential belongs to. Valid values:

  • authentication_token_provider: Authentication token provider.

authentication_token_provider

credentialSubjectId

string

The subject ID that the credential belongs to.

apt_werthgfdsasffxxxxx

credentialScenarioLabel

string

The Scenarios label of the credential. Valid values:

  • llm: Large language model.

  • saas: Third-party SaaS service.

llm

credentialType

string

The credential type. Valid values:

  • api_key: API Key authentication credential.

  • oauth_client: OAuth client authentication credential.

api_key

credentialCreationType

string

The creation type of the credential. Valid values:

  • system_init: Created by the system.

  • user_custom: Created by the user.

user_custom

description

string

The credential description.

credential_description

createTime

integer

The creation time, in UNIX timestamp format. Unit: milliseconds.

1649830225000

updateTime

integer

The update time, in UNIX timestamp format. Unit: milliseconds.

1649830227000

credentialContent

object

The credential content.

oauthClientContent

object

The credential content of the OAuth client authentication credential type.

clientId

string

The client_id for OAuth 2.0.

dmvncmxersdxxxxxx

clientSecret

string

The client_secret for OAuth 2.0.

nsklnertyt5ddwizncxxxx

apiKeyContent

object

The credential content of the API Key credential type.

apiKey

string

The API key value.

sk-nsklncmwizncxxxx

credentialSharingScope

string

The credential sharing scope.

user_exclusive

exclusiveUserId

string

The exclusive account ID of the credential.

user_xxx

credentialExternalId

string

The external unique identifier of the credential.

23528e9957304f57b98112c72788b5xxxxx

Examples

Success response

JSON format

{
  "instanceId": "idaas_ue2jvisn35ea5lmthk267xxxxx",
  "credentialId": "cred_mkv7rgt4d7i4u7zqtzev2mxxxx",
  "status": "enabled",
  "credentialIdentifier": "credential_identifier_test",
  "credentialName": "credential_name",
  "credentialSubjectType": "authentication_token_provider",
  "credentialSubjectId": "apt_werthgfdsasffxxxxx",
  "credentialScenarioLabel": "llm",
  "credentialType": "api_key",
  "credentialCreationType": "user_custom",
  "description": "credential_description",
  "createTime": 1649830225000,
  "updateTime": 1649830227000,
  "credentialContent": {
    "oauthClientContent": {
      "clientId": "dmvncmxersdxxxxxx",
      "clientSecret": "nsklnertyt5ddwizncxxxx"
    },
    "apiKeyContent": {
      "apiKey": "sk-nsklncmwizncxxxx\n"
    }
  },
  "credentialSharingScope": "user_exclusive",
  "exclusiveUserId": "user_xxx",
  "credentialExternalId": "23528e9957304f57b98112c72788b5xxxxx"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.