---
title: "List integration credentials"
method: GET
path: "/api/v1/integration_credentials"
tags: ["Integration Credential"]
---

# List integration credentials

`GET /api/v1/integration_credentials`

List all integration credential objects of the organization. Sensitive `secret` values are masked in the response.

## Query parameters

- `page_size` integer
- `cursor` string
- `id` string
- `name` string
- `type` 'coupa_sand_oauth2'
- `ordering` 'id' | '-id' | 'name' | '-name' | 'type' | '-type'

## Response `200`

OK

- object
  - `pagination` Pagination, required
    - `next` string, uri, nullable — URL for the next page of results. Contains an opaque signed `cursor` query parameter. Use this URL directly to fetch the next page — do not attempt to construct or modify the cursor value.
    - `previous` string, uri, nullable — URL for the previous page of results. Contains an opaque signed `cursor` query parameter. Use this URL directly to fetch the previous page — do not attempt to construct or modify the cursor value.
  - `results` IntegrationCredential[], required
    - `id` integer, required — Integration credential object ID.
    - `url` string, uri, required — Integration credential object URL.
    - `name` string, required — Name of the integration credential shown in the UI.
    - `type` 'coupa_sand_oauth2', required — Type of the credential; determines the shape of `secret`. Cannot be changed after creation.
    - `secret` object, required — When creating a credential or replacing the whole secret (PUT), `client_id`, `client_secret` and `base_api_url` are required. Partial updates (PATCH) may send any subset of the keys.
      - `client_id` string — OAuth2 client ID issued by Coupa. Masked as `[redacted...]` in responses.
      - `client_secret` string — OAuth2 client secret issued by Coupa. Masked as `[redacted...]` in responses.
      - `base_api_url` string, uri — Base URL of the Coupa instance API.
      - `scope` string — OAuth2 scopes requested for the token, separated by commas or spaces.
    - `hooks` string[], required — Hooks that use this credential.
    - `organization` string, uri, required — Organization URL.
    - `created_by` string, uri, required — User who created the integration credential.
    - `created_at` string, date-time, required — Timestamp of the integration credential creation.
    - `modified_by` string, uri, nullable, required — User that last modified the object.
    - `modified_at` string, date-time, nullable, required — Timestamp of last modification.

## Other responses

- `400` — Invalid input data.
- `401` — The username/password is invalid or token is invalid (e.g. expired).
- `403` — Insufficient permission, missing authentication, invalid CSRF token and similar issue.
- `404` — The specified resource was not found.
- `409` — Conflict
- `429` — Request rate is too high, wait before sending more requests. See [Rate Limiting](/guides/overview#rate-limiting) for more details.
- `500` — Server failure while processing the request.
- `502` — Invalid response from the upstream server.
- `503` — We're temporarily offline for maintenance. Please try again later.
- `504` — Upstream server could not complete the request in time.

---

[API](https://skmtc.dev/rossum/apis/rossum-api.md) · [All operations](https://skmtc.dev/rossum/apis/rossum-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/rossum/rossum-api/revisions/f1b5a910991d/schema)
