Gateway

Issue Gateway Credentials

Exchange the caller's credential for one that only the gateway accepts.

No permission check of its own: the result is strictly weaker than the credential that bought it — same tenant scope, same run, fewer routes — so a caller can reach nothing here it could not already reach with what it presented.

It does check the switch for the plane the caller named, because minting a credential for a plane that will refuse every request is worse than refusing here: the caller still has a pre-gateway path at this point and none once the run is under way.

post/gateways/credentials

Request body

plane'llm' | 'mcp'

Response

Successful Response

credentialsstring required

Changes

Changed in 1 of the 378 revisions of this API.1