---
title: "List vault credentials"
method: GET
path: "/vaults/{vault_id}/credentials"
tags: ["Vaults"]
---

# List vault credentials

`GET /vaults/{vault_id}/credentials`

Lists a vault's credentials using ID-based pagination without returning secret values. See [vaults](https://developers.openai.com/api/docs/guides/agents-api/tools/vaults).

## Path parameters

- `vault_id` string, required

## Query parameters

- `order` 'asc' | 'desc' — The order in which paginated resources are returned.
- `limit` integer, nullable
- `status` union — One or more lifecycle statuses to include when listing vaults or credentials.
  - 'active' | 'archived' — Whether a vault or credential is active or archived.
  - VaultStatusParam[]
- `after` string

## Response `200`

A page of vault credentials.

- VaultCredentialListResource — A page of Agents API resources, with IDs for retrieving additional pages.
  - `object` 'list', required — The object type, which is always `list`.
  - `data` VaultCredentialResource[], required — The resources returned in this page, in the requested sort order.
    - `id` string, required — The ID of the credential.
    - `object` 'vault.credential', required — The object type. Always `vault.credential`.
    - `vault_id` string, required — The ID of the vault containing this credential.
    - `name` string, required — The human-readable name of the credential.
    - `auth` union, required — The MCP server and authentication configuration of a vault credential, excluding secrets.
      - object — Public metadata for an OAuth credential; tokens and client secrets are never returned.
        - `type` 'mcp_oauth', required — The type of the object. Always `mcp_oauth`.
        - `mcp_server_url` string, required — The HTTPS MCP server URL authorized by this credential.
        - `expires_at` string, nullable, required — When the OAuth access token expires, as an RFC 3339 timestamp, if known.
        - `refresh` McpOauthRefreshResource, required — Configuration used to refresh an MCP OAuth access token, excluding secret values.
          - `token_endpoint` string, required — The HTTPS OAuth token endpoint used for refresh.
          - `client_id` string, required — The OAuth client ID used when requesting a new access token.
          - `resource` string, nullable, required — The resource URI sent to the OAuth token endpoint during refresh, if configured.
          - `scope` string, nullable, required — Space-separated OAuth scopes requested during refresh, if configured.
          - `token_endpoint_auth` union, required — The client authentication method used for OAuth token refresh.
            - object — Sends the client ID without a client secret.
              - …
            - object — Sends the client ID and secret using HTTP Basic authentication.
              - …
            - object — Sends the client ID and secret in the token request body.
              - …
      - object — Metadata for a bearer-token credential, without automatic OAuth refresh.
        - `type` 'static_bearer', required — The type of the object. Always `static_bearer`.
        - `mcp_server_url` string, required — The HTTPS MCP server URL authorized by this credential.
    - `created_at` integer, required — The Unix timestamp, in seconds, when the credential was created.
    - `updated_at` integer, required — The Unix timestamp, in seconds, when the credential was last updated.
  - `first_id` string, nullable, required — The ID of the first resource in `data`, or `null` if the page is empty.
  - `last_id` string, nullable, required — The ID of the last resource in `data`, or `null` if the page is empty. Pass this as `after` with the same order and filters.
  - `has_more` boolean, required — Whether there are more resources to retrieve after this page.

## Other responses

- `400` — The request was invalid.
- `401` — Authentication or project context was missing.
- `403` — The API key lacks the required management permission.
- `404` — The requested vault or credential was not found.
- `409` — The request conflicted with the current vault state.
- `500` — An internal error occurred.
- `503` — The service is temporarily unavailable.

## Changes

- **2026-09-10** `f2dae1a9aced` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openai/apis/openapi/changes/vaults/:vault_id/credentials/get.md)

---

[API](https://skmtc.dev/openai/apis/openapi.md) · [All operations](https://skmtc.dev/openai/apis/openapi/llms.txt) · [OpenAPI document](https://skmtc.dev/openai/apis/openapi/revisions/c8bd56db4095?raw)
