client_credentials pair. Until 1.8.0 Venly provisioned it for
you and a compromised secret meant a support ticket. You can now manage it through the API.
What a credential is
Who can call these endpoints
The four credential endpoints require themanage:credentials scope, and no API credential ever
holds it — it is a dashboard-user capability. That is deliberate: it means no credential can create,
rotate or disable another, so a leaked API secret cannot be used to mint a replacement for itself.
Plan for the consequence: if the only dashboard user holding manage:credentials is disabled or
leaves, restoring access to this surface requires Venly.
Create
Response (201)
secret in your secrets manager from this response. The
list endpoint has no secret field.
Rotate
1
Be ready to deploy
Have the place the new secret goes — your secrets manager, your config — ready to accept it.
2
Rotate
Call the endpoint and capture
result.secret.3
Deploy the new secret
Roll it out. Any service still holding the old secret fails its next token request, not its in-flight calls.
DISABLED credential (409 credential-disabled) — enable it first.
Disable and re-enable
clientId, secret, roles and history, and simply stops
issuing tokens. Setting ACTIVE again restores it unchanged.
If Venly provisioned more than one credential for your company before this endpoint existed, the
one-credential cap applies to re-enabling: while one is active, enabling another is refused with
409 credential-limit-exceeded, and there is no self-service way past it. For such a company,
disabling is how you converge on a single credential — do it deliberately.Errors
Next steps
Authentication
Turning the credential into a bearer token, and the scopes each endpoint needs.
Create API credentials
The endpoint reference.

