Fincore · API reference · Authentication
Retrieve client credentials
Base URL https://apicore.stg.finch.lat · operationId getClientCredentials
Returns the active credentials associated with a client. Use the client_secret returned here to create a bearer token with POST /v1/clients/{clientId}/auth/credential-tokens.
Authorization
x-api-keyAPI key sent in the x-api-key header. Create credentials from the Authentication guide before using protected endpoints.
Path parameters
clientId string (uuid) requiredThe unique identifier of the client.
Responses
200 A list of client credentials. application/json
data array of Credential requiredCredentials associated with the client.
id data[].id string (uuid) requiredThe unique identifier of the credential.
client_id data[].client_id string (uuid) requiredThe unique identifier of the client.
client_secret data[].client_secret string requiredSecret used with client_id to create a bearer token. Store it securely and never expose it in frontend code or logs.
environment data[].environment string requiredThe environment in which the credentials are valid.
staging production status data[].status string requiredThe status of the credentials.
ACTIVE INACTIVE created_at data[].created_at string (date-time) requiredTimestamp when the credentials were created.
updated_at data[].updated_at string (date-time) requiredTimestamp when the credentials were last updated.
deleted_at data[].deleted_at string | null requiredTimestamp when the credentials were deleted, or null if still active.
api_key data[].api_key string API key associated with the credentials when returned by the environment. Send this value in the x-api-key header for credential and token bootstrap calls.
400 Invalid credentials lookup request. Possible causes: malformed clientId path parameter or invalid request metadata. application/json
code integer requiredgRPC status code mapped to HTTP.
message string requiredGeneral error message.
details array of ErrorDetail requiredDetailed error causes returned by the service.
reason details[].reason string requiredMachine-readable error category.
DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL domain details[].domain string requiredService domain that produced the error.
metadata details[].metadata object requiredAdditional error metadata, including the detailed message and HTTP code.
error_detail details[].metadata.error_detail string Human-readable detail returned by the service.
http_code details[].metadata.http_code string HTTP status code associated with this error.
error_code details[].metadata.error_code string Optional internal error catalog code when available.
401 Authentication failed. Possible causes: missing x-api-key, invalid API key, or API key not valid for the requested environment. application/json
code integer requiredgRPC status code mapped to HTTP.
message string requiredGeneral error message.
details array of ErrorDetail requiredDetailed error causes returned by the service.
reason details[].reason string requiredMachine-readable error category.
DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL domain details[].domain string requiredService domain that produced the error.
metadata details[].metadata object requiredAdditional error metadata, including the detailed message and HTTP code.
error_detail details[].metadata.error_detail string Human-readable detail returned by the service.
http_code details[].metadata.http_code string HTTP status code associated with this error.
error_code details[].metadata.error_code string Optional internal error catalog code when available.
404 Client credentials were not found for the supplied clientId, or no active credential exists for the client. application/json
code integer requiredgRPC status code mapped to HTTP.
message string requiredGeneral error message.
details array of ErrorDetail requiredDetailed error causes returned by the service.
reason details[].reason string requiredMachine-readable error category.
DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL domain details[].domain string requiredService domain that produced the error.
metadata details[].metadata object requiredAdditional error metadata, including the detailed message and HTTP code.
error_detail details[].metadata.error_detail string Human-readable detail returned by the service.
http_code details[].metadata.http_code string HTTP status code associated with this error.
error_code details[].metadata.error_code string Optional internal error catalog code when available.
500 Unexpected server error. See Error catalog before retrying non-idempotent operations. application/json
code integer requiredgRPC status code mapped to HTTP.
message string requiredGeneral error message.
details array of ErrorDetail requiredDetailed error causes returned by the service.
reason details[].reason string requiredMachine-readable error category.
DATA_ERROR FAILED_PRECONDITION MISSING_REQUIRED_FIELDS RESOURCE_NOT_FOUND UNAUTHORIZED PERMISSION_DENIED UNIQUE_VIOLATION INTERNAL domain details[].domain string requiredService domain that produced the error.
metadata details[].metadata object requiredAdditional error metadata, including the detailed message and HTTP code.
error_detail details[].metadata.error_detail string Human-readable detail returned by the service.
http_code details[].metadata.http_code string HTTP status code associated with this error.
error_code details[].metadata.error_code string Optional internal error catalog code when available.
Request
curl -X GET "https://apicore.stg.finch.lat/v1/clients/c2d1d1e3-3340-4170-980e-e9269bbbc551/credentials" \
-H "x-api-key: $API_KEY"const res = await fetch("https://apicore.stg.finch.lat/v1/clients/c2d1d1e3-3340-4170-980e-e9269bbbc551/credentials", {
method: "GET",
headers: {
"x-api-key": API_KEY,
},
});
const data = await res.json();import requests
res = requests.get(
"https://apicore.stg.finch.lat/v1/clients/c2d1d1e3-3340-4170-980e-e9269bbbc551/credentials",
headers={
"x-api-key": API_KEY,
},
)
data = res.json()Response
{
"data": [
{
"id": "e981c6d8-4d49-45f2-a7ee-f956dca15500",
"client_id": "c2d1d1e3-3340-4170-980e-e9269bbbc551",
"client_secret": "client_secret_value",
"environment": "production",
"status": "ACTIVE",
"created_at": "2025-03-05T10:27:36.888241-06:00",
"updated_at": "2025-03-05T10:27:36.888241-06:00",
"deleted_at": null,
"api_key": "api_key_value"
}
]
}{
"code": 9,
"message": "API Error",
"details": [
{
"reason": "FAILED_PRECONDITION",
"domain": "CORE",
"metadata": {
"error_detail": "The account does not have sufficient funds.",
"http_code": "400",
"error_code": "10-E4120"
}
}
]
}{
"code": 9,
"message": "API Error",
"details": [
{
"reason": "FAILED_PRECONDITION",
"domain": "CORE",
"metadata": {
"error_detail": "The account does not have sufficient funds.",
"http_code": "400",
"error_code": "10-E4120"
}
}
]
}{
"code": 9,
"message": "API Error",
"details": [
{
"reason": "FAILED_PRECONDITION",
"domain": "CORE",
"metadata": {
"error_detail": "The account does not have sufficient funds.",
"http_code": "400",
"error_code": "10-E4120"
}
}
]
}{
"code": 9,
"message": "API Error",
"details": [
{
"reason": "FAILED_PRECONDITION",
"domain": "CORE",
"metadata": {
"error_detail": "The account does not have sufficient funds.",
"http_code": "400",
"error_code": "10-E4120"
}
}
]
}