Docs

Fincore · API reference · Authentication

Retrieve client credentials

GET /v1/clients/{clientId}/credentials
Try it ▸

Base URL https://apicore.stg.finch.lat · operationId getClientCredentials

Returns the active credentials associated with a client. Use the client_secret returned here to create a bearer token with POST /v1/clients/{clientId}/auth/credential-tokens.

Authorization

ApiKeyAuth API key in header x-api-key

API key sent in the x-api-key header. Create credentials from the Authentication guide before using protected endpoints.

Path parameters

clientId string (uuid) required

The unique identifier of the client.

Example c2d1d1e3-3340-4170-980e-e9269bbbc551

Responses

200 A list of client credentials. application/json
data array of Credential required

Credentials associated with the client.

id data[].id string (uuid) required

The unique identifier of the credential.

client_id data[].client_id string (uuid) required

The unique identifier of the client.

client_secret data[].client_secret string required

Secret used with client_id to create a bearer token. Store it securely and never expose it in frontend code or logs.

environment data[].environment string required

The environment in which the credentials are valid.

staging production
status data[].status string required

The status of the credentials.

ACTIVE INACTIVE
created_at data[].created_at string (date-time) required

Timestamp when the credentials were created.

updated_at data[].updated_at string (date-time) required

Timestamp when the credentials were last updated.

deleted_at data[].deleted_at string | null required

Timestamp when the credentials were deleted, or null if still active.

api_key data[].api_key string

API key associated with the credentials when returned by the environment. Send this value in the x-api-key header for credential and token bootstrap calls.

400 Invalid credentials lookup request. Possible causes: malformed clientId path parameter or invalid request metadata. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

401 Authentication failed. Possible causes: missing x-api-key, invalid API key, or API key not valid for the requested environment. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

404 Client credentials were not found for the supplied clientId, or no active credential exists for the client. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

500 Unexpected server error. See Error catalog before retrying non-idempotent operations. application/json
code integer required

gRPC status code mapped to HTTP.

message string required

General error message.

details array of ErrorDetail required

Detailed error causes returned by the service.

reason details[].reason string required

Machine-readable error category.

DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL
domain details[].domain string required

Service domain that produced the error.

metadata details[].metadata object required

Additional error metadata, including the detailed message and HTTP code.

error_detail details[].metadata.error_detail string

Human-readable detail returned by the service.

http_code details[].metadata.http_code string

HTTP status code associated with this error.

error_code details[].metadata.error_code string

Optional internal error catalog code when available.

This request is in the Monato · Fincore Postman collection, folder Authentication.Download collection

Request

curl -X GET "https://apicore.stg.finch.lat/v1/clients/c2d1d1e3-3340-4170-980e-e9269bbbc551/credentials" \
  -H "x-api-key: $API_KEY"

Response

{
  "data": [
    {
      "id": "e981c6d8-4d49-45f2-a7ee-f956dca15500",
      "client_id": "c2d1d1e3-3340-4170-980e-e9269bbbc551",
      "client_secret": "client_secret_value",
      "environment": "production",
      "status": "ACTIVE",
      "created_at": "2025-03-05T10:27:36.888241-06:00",
      "updated_at": "2025-03-05T10:27:36.888241-06:00",
      "deleted_at": null,
      "api_key": "api_key_value"
    }
  ]
}