---
title: "List vault credentials"
method: GET
path: "/vaults/{vault_id}/credentials"
tags: ["Vaults"]
---

# List vault credentials

`GET /vaults/{vault_id}/credentials`

Lists a vault's credentials using ID-based pagination without returning secret values. See [vaults](https://developers.openai.com/api/docs/guides/agents-api/tools/vaults).

## Path parameters

- `vault_id` string, required

## Query parameters

- `order` 'asc' | 'desc' — The order in which paginated resources are returned.
- `limit` integer, nullable
- `status` union — One or more lifecycle statuses to include when listing vaults or credentials.
  - 'active' | 'archived' — Whether a vault or credential is active or archived.
  - VaultStatusParam[]
- `after` string

## Response `200`

A page of vault credentials.

- VaultCredentialListResource — A page of Agents API resources, with IDs for retrieving additional pages.
  - `object` 'list', required — The object type, which is always `list`.
  - `data` VaultCredentialResource[], required — The resources returned in this page, in the requested sort order.
    - `id` string, required — The ID of the credential.
    - `object` 'vault.credential', required — The object type. Always `vault.credential`.
    - `vault_id` string, required — The ID of the vault containing this credential.
    - `name` string, required — The human-readable name of the credential.
    - `auth` union, required — The authentication configuration of a vault credential, excluding secrets.
      - object — Public metadata for an OAuth credential; tokens and client secrets are never returned.
        - `type` 'mcp_oauth', required — The type of the object. Always `mcp_oauth`.
        - `mcp_server_url` string, required — The HTTPS MCP server URL authorized by this credential.
        - `expires_at` string, nullable, required — When the OAuth access token expires, as an RFC 3339 timestamp, if known.
        - `refresh` McpOauthRefreshResource, required — Configuration used to refresh an MCP OAuth access token, excluding secret values.
          - `token_endpoint` string, required — The HTTPS OAuth token endpoint used for refresh.
          - `client_id` string, required — The OAuth client ID used when requesting a new access token.
          - `resource` string, nullable, required — The resource URI sent to the OAuth token endpoint during refresh, if configured.
          - `scope` string, nullable, required — Space-separated OAuth scopes requested during refresh, if configured.
          - `token_endpoint_auth` union, required — The client authentication method used for OAuth token refresh.
            - object — Sends the client ID without a client secret.
              - …
            - object — Sends the client ID and secret using HTTP Basic authentication.
              - …
            - object — Sends the client ID and secret in the token request body.
              - …
      - object — Metadata for a bearer-token credential, without automatic OAuth refresh.
        - `type` 'static_bearer', required — The type of the object. Always `static_bearer`.
        - `mcp_server_url` string, required — The HTTPS MCP server URL authorized by this credential.
      - object — Metadata for an HTTP credential used only in OpenAI-hosted environments. Sandbox code receives a placeholder. The proxy substitutes the secret for allowed HTTPS destinations on ports 443 and 8443. The real secret is not available to sandbox code for local computation and is never returned in this resource.
        - `type` 'environment_variable', required — The type of the object. Always `environment_variable`.
        - `secret_name` string, required — The environment variable name that receives the placeholder in the sandbox.
        - `networking` union, required — Destination permissions for an environment-variable credential. These do not grant network access to the environment.
          - object — Allows substitution for destinations permitted by the environment network policy. Requires `environment.network.access` to be `restricted`, with explicit `allowed_domains`.
            - `type` 'unrestricted', required — The type of the object. Always `unrestricted`.
          - object — Allows substitution only for the listed hosts. The environment network policy must also allow these hosts.
            - `type` 'limited', required — The type of the object. Always `limited`.
            - `allowed_hosts` string[], required — The 1 to 16 distinct allowed hostnames or IPv4 addresses, normalized to lowercase. Entries contain no scheme, path, port, or wildcard. IPv6 addresses are not supported.
    - `created_at` integer, required — The Unix timestamp, in seconds, when the credential was created.
    - `updated_at` integer, required — The Unix timestamp, in seconds, when the credential was last updated.
  - `first_id` string, nullable, required — The ID of the first resource in `data`, or `null` if the page is empty.
  - `last_id` string, nullable, required — The ID of the last resource in `data`, or `null` if the page is empty. Pass this as `after` with the same order and filters.
  - `has_more` boolean, required — Whether there are more resources to retrieve after this page.

## Other responses

- `400` — The request was invalid.
- `401` — Authentication or project context was missing.
- `403` — The API key lacks the required management permission.
- `404` — The requested vault or credential was not found.
- `409` — The request conflicted with the current vault state.
- `500` — An internal error occurred.
- `503` — The service is temporarily unavailable.

## Changes

- **2026-09-18** `ae9b7322bc4f` — 1 breaking, 1 info
  - added `#/components/schemas/VaultCredentialAuthResourceEnvironmentVariable` to the `data/items/auth` response property `oneOf` list for the response status `200`
  - added `environment_variable` discriminator mapping keys to the `data/items/auth` response property for the response status `200`
- **2026-09-10** `f2dae1a9aced` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openai/apis/openapi/changes/vaults/:vault_id/credentials/get.md)

---

[API](https://skmtc.dev/openai/apis/openapi.md) · [All operations](https://skmtc.dev/openai/apis/openapi/llms.txt) · [OpenAPI document](https://skmtc.dev/openai/apis/openapi/revisions/c40bf0ba89d2?raw)
