Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Get a connected account's credentials

GET/api/v1/connected_accounts/auth

Returns a connected account with its credentials, the user's OAuth tokens or the API key or other values they entered, so you can call the app yourself. If the OAuth access token has expired, Scalekit refreshes it first. Scalekit returns credentials only when credential access is turned on for your environment; to turn it on, contact Scalekit support. Until then, the response is the same as Get a connected account, with no authorization_details.

Authorization

Authorization: Bearer $TOKEN, an access token from the client credentials grant. See Authentication.

Query parameters

connectorstring
The connection name, as shown in AgentKit > Connections.
idstring
Unique identifier for the connected account
identifierstring
Your app's ID for the user, the same value you used when the user connected. Use a stable internal ID, not an email address.
organization_idstring
An organization ID to key the account by instead of identifier, such as a Scalekit organization ID. Ignored when identifier is set.
user_idstring
A user ID that, with organization_id, keys the account to one user in that organization. Ignored when identifier is set.

Response 200

connected_accountobject
The connected account.
Show 13 child attributes
api_configobject
Optional JSON configuration for connector-specific API settings such as rate limits, custom endpoints, or feature flags.
authorization_detailsobject
The account's credentials, in the shape for its auth type. Returned only when credential access is turned on for your environment.
Show 4 child attributes
google_dwdobject
Google Domain-Wide Delegation authentication — used for GOOGLE_DWD connections. Send only subject in requests; access_token, scopes, and token_expires_at are response-only.
oauth_tokenobject
OAuth 2.0 credentials.
static_authobject
Static credentials, such as an API key.
trusted_idpobject
Credentials for a connection that signs in through a trusted identity provider, such as AWS Redshift. Send only db_user. Responses include access_key_id and expiry, never the secret key or session token.
authorization_typestring (enum)
Type of authorization mechanism used. Specifies whether this connection uses OAuth, API keys, bearer tokens, or other auth methods.
OAUTHAPI_KEYBASIC_AUTHBEARER_TOKENCUSTOMBASICOAUTH_M2MTRELLO_OAUTH1GOOGLE_DWDTRUSTED_IDPSMART_FHIRNO_AUTH
connection_idstring
Reference to the parent connection configuration. Links this account to a specific connector setup in your environment.
connectorstring
The connection name, as shown in AgentKit > Connections.
idstring
Unique Scalekit-generated identifier for this connected account. Always prefixed with 'ca_'.
identifierstring
Your app's ID for the user, the value passed when the account was created.
is_org_wide_credentialboolean
Whether this is the shared credential of an org-wide connection, which every user's tool calls on that connection use. false for a user's own account.
last_used_atstring
Timestamp when this connected account was last used to make an API call. Useful for tracking active connections.
providerstring
The app the account connects to, such as GMAIL or SLACK.
statusstring (enum)
Current status of the connected account. Indicates if the account is active, expired, pending authorization, or pending user identity verification.
ACTIVEEXPIREDPENDING_AUTHPENDING_VERIFICATIONDISCONNECTED
token_expires_atstring
Expiration timestamp for the access token. After this time, the token must be refreshed or re-authorized.
updated_atstring
Timestamp when this connected account was last modified. Updated whenever credentials or configuration changes.

Errors

Every error has the same body: code, message and details. See Errors and rate limits.

400Invalid request - missing required query parameters
401Authentication required - missing or invalid access token
404Connected account not found - no account matches the specified criteria

Used in