Skip to main content
Your Finance API access is an OAuth client_credentials pair. Until 1.8.0 Venly provisioned it for you and a compromised secret meant a support ticket. You can now manage it through the API.

What a credential is

Each company holds one credential. Disabling it does not free the slot: the cap counts disabled credentials too, because a credential is never deleted. If you believe a secret is compromised, rotate it — don’t try to create a second one.

Who can call these endpoints

The four credential endpoints require the manage:credentials scope, and no API credential ever holds it — it is a dashboard-user capability. That is deliberate: it means no credential can create, rotate or disable another, so a leaked API secret cannot be used to mint a replacement for itself. Plan for the consequence: if the only dashboard user holding manage:credentials is disabled or leaves, restoring access to this surface requires Venly.

Create

Response (201)
Store secret in your secrets manager from this response. The list endpoint has no secret field.

Rotate

The old secret stops working immediately; tokens already issued against it stay valid until they expire (about five minutes). So the safe sequence is:
1

Be ready to deploy

Have the place the new secret goes — your secrets manager, your config — ready to accept it.
2

Rotate

Call the endpoint and capture result.secret.
3

Deploy the new secret

Roll it out. Any service still holding the old secret fails its next token request, not its in-flight calls.
Rotation is refused on a DISABLED credential (409 credential-disabled) — enable it first.

Disable and re-enable

Disabling is a pause: the credential keeps its clientId, secret, roles and history, and simply stops issuing tokens. Setting ACTIVE again restores it unchanged.
If Venly provisioned more than one credential for your company before this endpoint existed, the one-credential cap applies to re-enabling: while one is active, enabling another is refused with 409 credential-limit-exceeded, and there is no self-service way past it. For such a company, disabling is how you converge on a single credential — do it deliberately.

Errors

Next steps

Authentication

Turning the credential into a bearer token, and the scopes each endpoint needs.

Create API credentials

The endpoint reference.