> ## Documentation Index
> Fetch the complete documentation index at: https://docs.intelligence-management-platform.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit tool credentials

> Stores encrypted credentials for a `user_credentials`-enabled tool. Requires an authenticated session. The request body must include the one-time `nonce` emitted by the tool's credential request (encrypted, short-lived), plus a map of field names to values. The backend cross-checks the nonce's `userId` against the session user to prevent nonce-replay attacks. An optional `validate` hook on the tool config is called before persisting. On success the credentials are upserted and the tool can proceed on its next invocation.



## OpenAPI

````yaml /openapi/openapi.json post /credentials/submit
openapi: 3.1.0
info:
  title: IMP REST API
  version: 1.0.0
  description: >-
    REST endpoints of the IMP backend. GraphQL covers entity CRUD; REST covers
    agent runs, media, files, and system utilities. All requests require
    authentication unless the agent is public.
servers:
  - url: '{baseUrl}'
    variables:
      baseUrl:
        default: http://localhost:9001
        description: >-
          Base URL of your IMP backend. Self-hosted deployments typically run on
          port 9001.
security:
  - apiKey: []
  - bearer: []
tags:
  - name: Agents
    description: Endpoints for running, compacting, and querying agent instances.
  - name: Sessions
    description: Endpoints for managing files attached to agent sessions.
  - name: Media
    description: Transcription, speech synthesis, and image generation.
  - name: System
    description: Platform health and configuration utilities.
  - name: Budgets
    description: >-
      LiteLLM tag-budget management for users, roles, teams, projects, agents,
      and routines. Access requires `super_admin` or a role with
      `budget_management` write scope.
  - name: Skills
    description: >-
      Skills are versioned bundles of files (markdown, scripts, assets) mounted
      into the agent sandbox. These endpoints manage the skill registry and
      individual skill files.
  - name: Uploads
    description: >-
      Uppy-compatible S3 companion routes for single-part and multipart file
      uploads. Accept the standard API key. The `internal-key` header (set to
      `INTERNAL_SECRET`) is accepted only on `/s3/delete`, `/s3/download`,
      `/s3/list`, and `/s3/object` — it does **not** work on `/s3/sign` or the
      `/s3/multipart` routes.
  - name: Compliance
    description: >-
      GDPR / DSGVO operator endpoints for data-subject access (export) and
      erasure. Both require `super_admin`.
  - name: Artifacts
    description: >-
      Shareable artifact links — create, list, and revoke share links for files
      stored in S3.
  - name: Credentials
    description: >-
      Tool-credential management — submit, list, and revoke per-user credentials
      for oauth and user_credentials-enabled tools. Values are stored encrypted
      and never returned through these endpoints.
  - name: Public Agents
    description: >-
      Unauthenticated endpoints for guest-published agent discovery. Only
      whitelisted metadata fields are ever returned; no instructions, tools, or
      model details are exposed.
paths:
  /credentials/submit:
    post:
      tags:
        - Credentials
      summary: Submit tool credentials
      description: >-
        Stores encrypted credentials for a `user_credentials`-enabled tool.
        Requires an authenticated session. The request body must include the
        one-time `nonce` emitted by the tool's credential request (encrypted,
        short-lived), plus a map of field names to values. The backend
        cross-checks the nonce's `userId` against the session user to prevent
        nonce-replay attacks. An optional `validate` hook on the tool config is
        called before persisting. On success the credentials are upserted and
        the tool can proceed on its next invocation.
      operationId: submitCredentials
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - nonce
                - values
              properties:
                nonce:
                  type: string
                  description: >-
                    One-time encrypted nonce from the tool's `credentialRequest`
                    payload. Short-lived; re-prompt on expiry.
                values:
                  type: object
                  additionalProperties:
                    type: string
                  description: >-
                    Map of field name to user-supplied value. Must exactly match
                    the field set declared by the tool config.
            example:
              nonce: eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0...
              values:
                api_key: sk-...
                workspace_id: ws_abc123
      responses:
        '200':
          description: Credentials stored.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    example: true
                required:
                  - ok
        '400':
          description: >-
            Invalid body, field-set mismatch, unknown provider, or validation
            hook failed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    example: false
                  error:
                    type: string
                required:
                  - ok
        '401':
          description: Not authenticated or nonce expired / invalid.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    example: false
                  error:
                    type: string
                required:
                  - ok
        '403':
          description: Nonce `userId` does not match the session user.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    example: false
                  error:
                    type: string
                required:
                  - ok
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organisation API key. Format: `sk_<secret>/<keyname>` — the secret
        portion, a literal slash, and the human-readable key name. The header
        `exulu-api-key` is accepted as an alias. A `Bearer ` prefix is tolerated
        and stripped. Keys with an agent scope are only valid for the scoped
        agent instance.
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        NextAuth session JWT (HS256, signed with `NEXTAUTH_SECRET`). This is the
        token the IMP frontend uses automatically.

````