Retrieve the qiyaov Platform API Credential List

List business API credentials with pagination. This response currently contains sensitive fields for Token or Identity credentials, which must only be handled on the server side and must not be written to logs, analytics platforms, frontend storage, or public repositories.

Preparation

Create an Account Token, and obtain the current account UUID through GET /api/v1/platform-tokens/me/.

export PLATFORM_TOKEN='your account token'
export USER_ID='your account UUID'

API Overview

Item Content
Method GET
URL https://api17.platform.acedata.cloud/api/v1/credentials/
Auth Account Token; OAuth token requires credentials:read
Pagination count + items

Regular users should provide their own user_id or an authorized application_id; otherwise, the request may return 403 when pagination encounters unauthorized objects.

Query Parameters

Parameter Type Required Description
user_id string Depends on scenario Credential holder; repeated parameters are supported
application_id UUID No Filter by Application; repeated parameters are supported
host string No Exact filter by host; repeated parameters are supported
name string No Exact filter by name; repeated parameters are supported
granted boolean No true for credentials granted to others, false for self-use credentials
limit / offset integer No Pagination
ordering string No created_at or -created_at

service_id, disabled, and expired are currently not filtering parameters.

curl --get 'https://api17.platform.acedata.cloud/api/v1/credentials/' \
  --data-urlencode "user_id=${USER_ID}" \
  --data-urlencode 'limit=100' \
  -H "Authorization: Bearer ${PLATFORM_TOKEN}"

Response Description

The response verified in production is {count, items}. Each item contains id, application_id, application, user_id, creator_id, name, type, limited_amount, used_amount, expired_at, allowed_api_ids, host, granted, granted_to_user_id, tags, metadata, and time fields, and returns token or username/password according to the type.

The current list response returns complete sensitive values. Do not expose them in browser consoles or collection systems, and do not rely on recovering plaintext through the list; clients should be compatible with future masking strategies.

Next Steps