Provide an API credential when requested

Available broadlyLast reviewed

Some external API tasks need a credential that is separate from an app's normal sign-in flow. A teammate can request that value through a masked field and save it for an identified API destination.

Use the requested field

Tell the teammate which API you want it to use and what the credential is for. When it presents the protected request, inspect the label and destination, then enter the credential in the masked field.

Try this

I want you to use our reporting API at [HTTPS API origin]. Ask me for a named API credential through the protected input flow, then retrieve the current report using that saved credential.

Saved credentials are associated with the requesting teammate and user, and with the stated HTTPS origin. The teammate can inspect saved names and destinations without retrieving the secret value.

Update or remove a credential

Ask to replace the named credential if the API issues a new value. Ask the teammate to forget that credential when it should stop using it.

Website login is different

For a password, passkey, CAPTCHA, or two-factor step inside a website, use the computer takeover flow and complete the step directly on the screen. A connector may instead request a one-use code through its own protected input.

If the task is paused, finish the pending input request and let the same task continue. Avoid starting several duplicate attempts to supply the same credential.