Skip to main content
POST
Create API credentials
Requires scope: manage:credentials — see Required scopes. Creates a client-credentials pair and returns its secret in this response only. Record it now; a lost secret is replaced by rotating, never by reading it back. The clientId is server-generated from your company and the name you supply. Each company holds one credential; disabling it does not free the slot. See API credentials.

Errors

Authorizations

FlowClient Credentials
Token URL
https://login-staging.venly.io/auth/realms/VenlyFinance/protocol/openid-connect/token

Headers

x-tenant-id
string<uuid>

Which tenant the request is scoped to, among those your token grants. Omit it when the token grants exactly one tenant; it is required when the token grants more than one. A supplied value must exactly match a tenant the token grants.

Absent when required, blank, malformed, or naming a tenant the token does not grant — each gets the same generic 403 forbidden, which reveals neither whether a tenant exists nor which ones you may use. Send the header once: a repeated header is rejected the same way.

Example:

"3fa85f64-5717-4562-b3fc-2c963f66afa6"

Body

application/json

Only a label is supplied — the clientId is derived server-side and can never be chosen by the caller.

name
string
required

Your own label for the credential, e.g. the service that will use it. Must not be blank.

Required string length: 1 - 100
Example:

"checkout-service"

Response

Credential created. The secret is present in this response only.

success
boolean

Indicates whether the request was successful

result
object

A credential together with its secret. Returned by create and rotate only. Record the secret immediately: Finance does not store it, no endpoint returns it afterwards, and a lost secret is replaced by rotating the credential rather than by reading it.