← Documentation

Credential Security

Issuance, hashing, scopes, attribution, spending limits, risk response, rotation, and revocation.

{
  "version": "2026-08-v6",
  "storage": "Full secrets are displayed once and never stored as recoverable plaintext.",
  "identifier": "A non-secret prefix and credential ID may be displayed and logged.",
  "management": [
    "POST /v1/account/credentials/rotate",
    "POST /v1/account/credentials/{credential_id}/revoke",
    "POST /v1/account/credentials/revoke-all",
    "POST /v1/security/freeze"
  ],
  "risk_levels": [
    "low: monitor",
    "medium: restrict expensive work and verify",
    "high: lock/revoke affected credential",
    "critical: revoke and freeze affected account"
  ],
  "limits": "Protective suspension is not a determination of wrongdoing."
}

Machine-readable response