Create qiyaov Platform API Credentials

Create business API credentials for an Application. The creation response may contain a Token that can directly call https://api.qiyaov.com/**, or a username/password for Proxy-type credentials; they must be treated as secrets.

Preparation

  1. Create an Account Token.
  2. Obtain the application_id that you own from the Application list.
export PLATFORM_TOKEN='your account token'
export APPLICATION_ID='your Application ID'

API Overview

Item Content
Method POST
URL https://api17.platform.acedata.cloud/api/v1/credentials/
Auth Account Token, OAuth token requires credentials:write
Body JSON

Request Body

Field Type Required Description
application_id UUID Yes Target Application
name string No Credential display name
limited_amount number / null No Usage limit per credential; null means no independent limit
expired_at datetime / null No ISO 8601 expiration time
allowed_api_ids UUID[] / null No Only allow calling these APIs; an empty array is normalized to no restriction
host string No Credential host information
for_user_id string No Used when the Application owner issues delegated credentials for another user
tags / metadata array / object No Custom extension data
curl -X POST 'https://api17.platform.acedata.cloud/api/v1/credentials/' \
  -H "Authorization: Bearer ${PLATFORM_TOKEN}" \
  -H 'Content-Type: application/json' \
  -d "{\"application_id\":\"${APPLICATION_ID}\",\"name\":\"production\",\"limited_amount\":50}"

Response Description

A successful response returns 201 and a Credential object:

  • API/Agent-type services usually return type=Token and token;
  • Proxy-type services usually return type=Identity and username / password, and a Proxy Application allows only one credential;
  • id, user_id, creator_id, used_amount, and time fields are generated by the server.

The current list and detail APIs also return credentials in plaintext, but clients should not rely on this historical behavior. Save them immediately after creation and avoid writing the response to logs; future APIs may return masked values.

Error Handling

  • 400: Invalid field format, unknown allowed_api_ids, the Proxy Application already has credentials, or other creation constraints.
  • 401: Invalid Account Token.
  • 403/404: No permission to access the target Application, or the Application/delegated user does not exist.

Next Steps