Retrieve the qiyaov Platform API Credential List
List business API credentials with pagination. This response currently contains sensitive fields for Token or Identity credentials, which must only be handled on the server side and must not be written to logs, analytics platforms, frontend storage, or public repositories.
¶ Preparation
Create an Account Token, and obtain the current account UUID through GET /api/v1/platform-tokens/me/.
export PLATFORM_TOKEN='your account token'
export USER_ID='your account UUID'
¶ API Overview
| Item | Content |
|---|---|
| Method | GET |
| URL | https://api17.platform.acedata.cloud/api/v1/credentials/ |
| Auth | Account Token; OAuth token requires credentials:read |
| Pagination | count + items |
Regular users should provide their own user_id or an authorized application_id; otherwise, the request may return 403 when pagination encounters unauthorized objects.
¶ Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
user_id |
string | Depends on scenario | Credential holder; repeated parameters are supported |
application_id |
UUID | No | Filter by Application; repeated parameters are supported |
host |
string | No | Exact filter by host; repeated parameters are supported |
name |
string | No | Exact filter by name; repeated parameters are supported |
granted |
boolean | No | true for credentials granted to others, false for self-use credentials |
limit / offset |
integer | No | Pagination |
ordering |
string | No | created_at or -created_at |
service_id, disabled, and expired are currently not filtering parameters.
curl --get 'https://api17.platform.acedata.cloud/api/v1/credentials/' \
--data-urlencode "user_id=${USER_ID}" \
--data-urlencode 'limit=100' \
-H "Authorization: Bearer ${PLATFORM_TOKEN}"
¶ Response Description
The response verified in production is {count, items}. Each item contains id, application_id, application, user_id, creator_id, name, type, limited_amount, used_amount, expired_at, allowed_api_ids, host, granted, granted_to_user_id, tags, metadata, and time fields, and returns token or username/password according to the type.
The current list response returns complete sensitive values. Do not expose them in browser consoles or collection systems, and do not rely on recovering plaintext through the list; clients should be compatible with future masking strategies.