Skip to main content
POST
Issue credentials after exact fresh approval
Preview contract. Production availability remains subject to activation and release qualification. Examples are synthetic; the documentation cannot submit requests.

Authorization

Authenticated Settings session and exact fresh purpose-bound approval.

Behavior

Submit the same operation_id and full approved request. A new issuance returns 201 with a one-time secret; a committed duplicate can return 200 metadata without recovering the secret. Do not automatically repeat after a lost response. This is a session-owned application contract, not an ordinary API-key endpoint. Use Settings → Integrations. The public API base URL does not grant session access.

JSON body example

The following shows the request shape, not live credentials or executable market defaults. Replace timestamps only when creating a new reviewed intent; never mutate them on a command retry.

Response and errors

The generated response schema below is the wire contract. Preserve fixed-point strings, nullable fields and endpoint-specific envelopes. Inspect HTTP status and Content-Type before decoding failures; reused trading routes may return JSON or plain text. Authentication, entitlement and exact link/instrument restrictions apply in addition to endpoint validation. See errors and recovery. Do not automatically repeat a mutation after transport ambiguity. Trading commands reuse the exact immutable identity; credential issuance and template writes require their documented metadata/read reconciliation. Read the related guide for lifecycle, units and recovery semantics.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
operation_id
string<uuid>
required
request
object
required

Response

Committed duplicate; no secret recovery

Secret only on first successful issue; duplicates return metadata. Never automatically repeat issuance after ambiguity.

credential
object
required
binding
object
secret
string
read-only

One-time secret on successful first issuance only.

webhook_url
string<uri>