Endpoint
Authentication
Requires the developer API key (not a grant token). The caller is the relying
party that injects the credential upstream, such as @grantex/gateway with
credentialReference: on. The agent itself never calls this endpoint and never
holds the credential.
Available when the auth service runs with VAULT_CREDENTIAL_REFERENCES_ENABLED=true
(the exchange hands out references only then).
Request Body
Example Request
Response — 200 OK
What is checked
- The reference exists and was issued under the caller’s developer account.
grantId is the grant the reference was issued to.
- The reference has not expired (
VAULT_CREDENTIAL_REFERENCE_TTL_SECONDS, 300 by default; a reference is also never issued beyond the expiry of the grant token that obtained it).
- The grant is still active and unexpired: a revoked grant, one an emergency stop ended, or one past its own expiry refuses the reference with it.
Each resolution is recorded on the reference (resolved_count, last_resolved_at) and
emits vault.credential.resolved.
Error Responses
Rate Limits
This endpoint is limited to 120 requests per minute per API key.Last modified on October 2, 2026