curl --request POST \
--url https://api.onkernel.com/org/credential_providers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "my-1password",
"provider_type": "onepassword",
"token": "ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"cache_ttl_seconds": 300
}
'import requests
url = "https://api.onkernel.com/org/credential_providers"
payload = {
"name": "my-1password",
"provider_type": "onepassword",
"token": "ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"cache_ttl_seconds": 300
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'my-1password',
provider_type: 'onepassword',
token: 'ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...',
cache_ttl_seconds: 300
})
};
fetch('https://api.onkernel.com/org/credential_providers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.onkernel.com/org/credential_providers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'my-1password',
'provider_type' => 'onepassword',
'token' => 'ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...',
'cache_ttl_seconds' => 300
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.onkernel.com/org/credential_providers"
payload := strings.NewReader("{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.onkernel.com/org/credential_providers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.onkernel.com/org/credential_providers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}"
response = http.request(request)
puts response.read_body{
"created_at": "2025-01-15T10:30:00Z",
"enabled": true,
"id": "credprov_abc123xyz",
"name": "my-1password",
"priority": 0,
"provider_type": "onepassword",
"updated_at": "2025-01-15T10:30:00Z"
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}Create a credential provider
Configure an external credential provider (e.g., 1Password) for automatic credential lookup.
curl --request POST \
--url https://api.onkernel.com/org/credential_providers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "my-1password",
"provider_type": "onepassword",
"token": "ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"cache_ttl_seconds": 300
}
'import requests
url = "https://api.onkernel.com/org/credential_providers"
payload = {
"name": "my-1password",
"provider_type": "onepassword",
"token": "ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"cache_ttl_seconds": 300
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'my-1password',
provider_type: 'onepassword',
token: 'ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...',
cache_ttl_seconds: 300
})
};
fetch('https://api.onkernel.com/org/credential_providers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.onkernel.com/org/credential_providers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'my-1password',
'provider_type' => 'onepassword',
'token' => 'ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...',
'cache_ttl_seconds' => 300
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.onkernel.com/org/credential_providers"
payload := strings.NewReader("{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.onkernel.com/org/credential_providers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.onkernel.com/org/credential_providers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"my-1password\",\n \"provider_type\": \"onepassword\",\n \"token\": \"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...\",\n \"cache_ttl_seconds\": 300\n}"
response = http.request(request)
puts response.read_body{
"created_at": "2025-01-15T10:30:00Z",
"enabled": true,
"id": "credprov_abc123xyz",
"name": "my-1password",
"priority": 0,
"provider_type": "onepassword",
"updated_at": "2025-01-15T10:30:00Z"
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}{
"code": "bad_request",
"message": "Missing required field: app_name",
"details": [
{
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
],
"inner_error": {
"code": "invalid_input",
"message": "Provided version string is not semver compliant"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Request to create an external credential provider
Human-readable name for this provider instance (unique per org). Surrounding whitespace is trimmed and the trimmed value must be non-empty.
1\S"my-1password"
Type of credential provider
onepassword "onepassword"
Service account token for the provider (e.g., 1Password service account token)
"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9..."
How long to cache credential lists (default 300 seconds)
300
Response
Credential provider created successfully
An external credential provider (e.g., 1Password) for automatic credential lookup
When the credential provider was created
"2025-01-15T10:30:00Z"
Whether the provider is enabled for credential lookups
true
Unique identifier for the credential provider
"credprov_abc123xyz"
Human-readable name for this provider instance
"my-1password"
Priority order for credential lookups (lower numbers are checked first)
0
Type of credential provider
onepassword "onepassword"
When the credential provider was last updated
"2025-01-15T10:30:00Z"