---
title: "List toolkit credential bindings"
method: GET
path: "/toolkits/{toolkit_id}/credentials"
tags: ["Toolkit Credentials"]
---

# List toolkit credential bindings

`GET /toolkits/{toolkit_id}/credentials`

List the credentials bound to a toolkit with cursor-based pagination.

## Path parameters

- `toolkit_id` string, required

## Query parameters

- `cursor` string, nullable
- `limit` integer

## Response `200`

Successful Response

- ToolkitCredentialListResponse — Paginated list of credential bindings.
  - `data` ToolkitCredentialBindingResponse[], required
    - `api_name` string, nullable
    - `api_vendor` string, nullable
    - `bound_at` string, date-time, required
    - `catalog_api_id` string, nullable — Catalog identity slug of the bound credential's target API (`domain[/sub-api]`), when recorded. Display-only.
    - `credential_id` string, required
    - `credential_type` string, nullable
    - `label` string, nullable
    - `permissions` PermissionRuleReadSchema[]
      - `_comment` string, nullable
      - `_system` boolean
      - `effect` 'allow' | 'deny', required
      - `match_mode` 'regex' | 'prefix' | 'exact'
      - `methods` string[], nullable
      - `operations` string[], nullable
      - `path` string, nullable
    - `toolkit_id` string, required
    - `warnings` BindingWarningSchema[] — Non-fatal bind-time signals — e.g. a binding that landed with zero permission rules (broker denies by default until rules are added).
      - `code` string, required — Stable machine-readable warning code.
      - `credential_id` string, nullable — Credential the warning applies to; null when the whole binding is meant.
      - `message` string, required — Human-readable explanation with a recovery pointer.
  - `has_more` boolean, required
  - `next_cursor` string, nullable

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-07-31** `3746d110464c` — 1 info
  - added the optional property `data/items/catalog_api_id` to the response with the `200` status
- **2026-07-24** `6b93e5cc002c` — 2 info
  - added the optional property `data/items/permissions/items/match_mode` to the response with the `200` status
  - added the optional property `data/items/warnings` to the response with the `200` status
- **2026-07-01** `d65fcba0d25a` — 2 breaking, 26 info
  - the response's body type/format changed from `array`/`` to `object`/`` for status `200`
  - the `detail` response's property type/format changed from `array`/`` to `string`/`` for status `422`
  - api operation id `list_toolkit_credentials_toolkits__toolkit_id__credentials_get` removed and replaced with `listBindings`
  - the endpoint scheme security `BearerAuth` was added to the API
  - …24 more
- **2026-05-07** `5a765d68c56f` — 1 info
  - the endpoint scheme security `AgentOauthAccessToken` was added to the API
- **2026-04-13** `76e8f6063728` — 7 breaking, 9 warning, 12 info
  - the response's body type/format changed from `object`/`` to `array`/`` for status `200`
  - media type `application/problem+json` was changed to a more general media type `application/json` for the response status `422`
  - the response property `detail` became optional for the status `422`
  - the `detail` response property's maxLength was unset from `4096` for the response status `422`
  - …24 more

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/toolkits/:toolkit_id/credentials/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/jentic/jentic-control-plane-api/revisions/f4594f50f4d3/schema)
