Create qiyaov Platform API Credentials
Create business API credentials for an Application. The creation response may contain a Token that can directly call https://api.qiyaov.com/**, or a username/password for Proxy-type credentials; they must be treated as secrets.
¶ Preparation
- Create an Account Token.
- Obtain the
application_idthat you own from the Application list.
export PLATFORM_TOKEN='your account token'
export APPLICATION_ID='your Application ID'
¶ API Overview
| Item | Content |
|---|---|
| Method | POST |
| URL | https://api17.platform.acedata.cloud/api/v1/credentials/ |
| Auth | Account Token, OAuth token requires credentials:write |
| Body | JSON |
¶ Request Body
| Field | Type | Required | Description |
|---|---|---|---|
application_id |
UUID | Yes | Target Application |
name |
string | No | Credential display name |
limited_amount |
number / null | No | Usage limit per credential; null means no independent limit |
expired_at |
datetime / null | No | ISO 8601 expiration time |
allowed_api_ids |
UUID[] / null | No | Only allow calling these APIs; an empty array is normalized to no restriction |
host |
string | No | Credential host information |
for_user_id |
string | No | Used when the Application owner issues delegated credentials for another user |
tags / metadata |
array / object | No | Custom extension data |
curl -X POST 'https://api17.platform.acedata.cloud/api/v1/credentials/' \
-H "Authorization: Bearer ${PLATFORM_TOKEN}" \
-H 'Content-Type: application/json' \
-d "{\"application_id\":\"${APPLICATION_ID}\",\"name\":\"production\",\"limited_amount\":50}"
¶ Response Description
A successful response returns 201 and a Credential object:
- API/Agent-type services usually return
type=Tokenandtoken; - Proxy-type services usually return
type=Identityandusername/password, and a Proxy Application allows only one credential; id,user_id,creator_id,used_amount, and time fields are generated by the server.
The current list and detail APIs also return credentials in plaintext, but clients should not rely on this historical behavior. Save them immediately after creation and avoid writing the response to logs; future APIs may return masked values.
¶ Error Handling
400: Invalid field format, unknownallowed_api_ids, the Proxy Application already has credentials, or other creation constraints.401: Invalid Account Token.403/404: No permission to access the target Application, or the Application/delegated user does not exist.