Skip to main content

Endpoint

Authentication

Requires the developer API key (not a grant token). The caller is the relying party that injects the credential upstream, such as @grantex/gateway with credentialReference: on. The agent itself never calls this endpoint and never holds the credential. Available when the auth service runs with VAULT_CREDENTIAL_REFERENCES_ENABLED=true (the exchange hands out references only then).

Request Body

Example Request

Response — 200 OK

What is checked

  1. The reference exists and was issued under the caller’s developer account.
  2. grantId is the grant the reference was issued to.
  3. The reference has not expired (VAULT_CREDENTIAL_REFERENCE_TTL_SECONDS, 300 by default; a reference is also never issued beyond the expiry of the grant token that obtained it).
  4. The grant is still active and unexpired: a revoked grant, one an emergency stop ended, or one past its own expiry refuses the reference with it.
Each resolution is recorded on the reference (resolved_count, last_resolved_at) and emits vault.credential.resolved.

Error Responses

Rate Limits

This endpoint is limited to 120 requests per minute per API key.
Last modified on October 2, 2026