generated: '2026-07-18' method: searched source: https://credentially.readme.io/reference/getting-started-with-your-api docs: https://credentially.readme.io/reference/getting-started-with-your-api apis: - openapi/credentially-gateway-openapi-original.json - openapi/credentially-webhook-openapi-original.json authentication: style: bearer-token scheme: http bearer format: JWT header: 'Authorization: Bearer ' provisioning: API keys are issued by a Credentially Customer Success Manager / support@credentially.io; no self-service key generation. cross_ref: authentication/credentially-authentication.yml regions: note: The same API is served from region-pinned gateways; pick the host matching the customer's data residency. hosts: - region: EU/UK base: https://app.credentially.io/gateway - region: US base: https://us.credentially.io/gateway - region: CA base: https://ca.credentially.io/gateway pagination: style: page-number evidence: Paginated list endpoints (Load Profiles, List placements, placement notes) return a PlacementPageDto / ProfileListPageDto / PlacementNotePageDto envelope with a Meta block; List All Profiles (Lightweight) is the non-paginated variant. response_envelope_fields: - meta rate_limiting: style: per-operation named buckets signal: HTTP 429 Too Many Requests on exceed evidence: Every documented operation carries a named rate-limit bucket and quota (e.g. dictionary-lookup 100 req/1s, create-profile 25 req/1s, profile-metadata 10 req/10s, load-all-profiles 5 req/1s). cross_ref: llms/credentially-llms.txt idempotency: request_keys: false note: The REST API does not document an Idempotency-Key request header. Idempotency is documented on the webhook DELIVERY side only. webhook_delivery: duplicate_deliveries: possible guidance: Receivers must be idempotent; strict ordering is not guaranteed and duplicate deliveries can occur after timeouts or transient errors. retries: after 30s, then 60s, 120s ... doubling backoff, up to 14 attempts ack_window: handlers must return 2xx within 15s or the callback is re-sent cross_ref: asyncapi/credentially-webhooks.yml versioning: scheme: spec-version current: 2.0.0 note: Both the Gateway (Public API 2.0.0) and Webhook (2.0.0) OpenAPI documents are versioned; no URI/date version segment in the path. cross_ref: lifecycle/credentially-lifecycle.yml error_envelope: format: http-status problem_json: false note: Errors are signalled by HTTP status code (400/401/403/404/409/413/429/500); no application/problem+json body is declared. cross_ref: errors/credentially-problem-types.yml