{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/openai/main/json-schema/openai-create-vault-credential-params-schema.json", "title": "CreateVaultCredentialParams", "description": "Parameters for storing a credential for an MCP server or an OpenAI-hosted environment.", "x-generated": "2026-09-23", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/openai-vaults-api-openapi.yml#/components/schemas/CreateVaultCredentialParams", "type": "object", "properties": { "name": { "type": "string", "minLength": 1, "maxLength": 1048576, "description": "The name is trimmed before storage. It must contain 1 to 256 UTF-8 bytes after trimming." }, "auth": { "$ref": "#/$defs/CreateVaultCredentialAuthParam", "description": "The authentication method and write-only secret values to store." }, "metadata": { "type": "object", "additionalProperties": { "type": "string", "minLength": 0, "maxLength": 512 }, "propertyNames": { "type": "string", "minLength": 1, "maxLength": 64 }, "minProperties": 0, "maxProperties": 16, "description": "Up to 16 string key-value pairs, with keys up to 64 and values up to 512 characters. Defaults to an empty map." } }, "required": [ "auth", "name" ], "additionalProperties": false, "$defs": { "CreateMcpOauthRefreshParam": { "type": "object", "properties": { "token_endpoint": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The HTTPS OAuth token endpoint used to exchange the refresh token for a new access token." }, "client_id": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The OAuth client ID used when requesting a new access token." }, "resource": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "The resource URI to send to the OAuth token endpoint during refresh, if required." }, "scope": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "Space-separated OAuth scopes to request during refresh, if required." }, "refresh_token": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The refresh token to store. This secret is never returned in credential resources." }, "token_endpoint_auth": { "$ref": "#/$defs/CreateMcpOauthTokenEndpointAuthParam", "description": "How the OAuth client authenticates to the token endpoint." } }, "required": [ "token_endpoint", "client_id", "refresh_token", "token_endpoint_auth" ], "additionalProperties": false, "description": "Configuration for refreshing the access token of an MCP OAuth credential." }, "CreateMcpOauthTokenEndpointAuthParam": { "oneOf": [ { "$ref": "#/$defs/CreateMcpOauthTokenEndpointAuthParamNone" }, { "$ref": "#/$defs/CreateMcpOauthTokenEndpointAuthParamClientSecretBasic" }, { "$ref": "#/$defs/CreateMcpOauthTokenEndpointAuthParamClientSecretPost" } ], "x-oai-discriminator-values": [ "none", "client_secret_basic", "client_secret_post" ], "description": "Client authentication credentials for OAuth token refresh." }, "CreateMcpOauthTokenEndpointAuthParamClientSecretBasic": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "client_secret_basic" ], "default": "client_secret_basic", "x-stainless-const": true, "description": "The type of the object. Always `client_secret_basic`." }, "client_secret": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The OAuth client secret to store. Never returned in credential resources." } }, "required": [ "type", "client_secret" ], "additionalProperties": false, "description": "Sends the client ID and secret using HTTP Basic authentication." }, "CreateMcpOauthTokenEndpointAuthParamClientSecretPost": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "client_secret_post" ], "default": "client_secret_post", "x-stainless-const": true, "description": "The type of the object. Always `client_secret_post`." }, "client_secret": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The OAuth client secret to store. Never returned in credential resources." } }, "required": [ "type", "client_secret" ], "additionalProperties": false, "description": "Sends the client ID and secret in the token request body." }, "CreateMcpOauthTokenEndpointAuthParamNone": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "none" ], "default": "none", "x-stainless-const": true, "description": "The type of the object. Always `none`." } }, "required": [ "type" ], "additionalProperties": false, "description": "Sends the client ID without a client secret." }, "CreateVaultCredentialAuthParam": { "oneOf": [ { "$ref": "#/$defs/CreateVaultCredentialAuthParamMcpOauth" }, { "$ref": "#/$defs/CreateVaultCredentialAuthParamStaticBearer" }, { "$ref": "#/$defs/CreateVaultCredentialAuthParamEnvironmentVariable" } ], "x-oai-discriminator-values": [ "mcp_oauth", "static_bearer", "environment_variable" ], "description": "Authentication credentials for an MCP server or an OpenAI-hosted environment." }, "CreateVaultCredentialAuthParamEnvironmentVariable": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "environment_variable" ], "default": "environment_variable", "x-stainless-const": true, "description": "The type of the object. Always `environment_variable`." }, "secret_name": { "type": "string", "minLength": 1, "maxLength": 1048576, "description": "The environment variable name that receives the placeholder, such as `SERVICE_API_KEY`. Use ASCII letters, digits, and underscores, starting with a letter or underscore. Names starting with `CODEX_` and managed proxy or certificate variable names are reserved." }, "secret_value": { "type": "string", "minLength": 1, "maxLength": 1048576, "description": "The write-only secret to store. Never returned in credential resources or supplied directly to sandbox code. Must be nonempty and must not contain carriage returns, newlines, or NUL bytes." }, "networking": { "$ref": "#/$defs/VaultCredentialNetworkingParam", "description": "The destinations where the proxy can substitute this secret. The environment network policy must also allow them." } }, "required": [ "type", "secret_name", "secret_value", "networking" ], "additionalProperties": false, "description": "An HTTP credential for OpenAI-hosted environments only. The sandbox receives an environment variable containing a placeholder, not the secret. Use the placeholder unchanged in outgoing requests. The egress proxy replaces the placeholder with the secret for allowed HTTPS destinations on ports 443 and 8443. Sandbox code cannot read the real secret or use it for local computation, such as signing a request." }, "CreateVaultCredentialAuthParamMcpOauth": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "mcp_oauth" ], "default": "mcp_oauth", "x-stainless-const": true, "description": "The type of the object. Always `mcp_oauth`." }, "mcp_server_url": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The HTTPS MCP server URL authorized by this credential." }, "access_token": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "A write-only OAuth access token; never returned by credential resources." }, "expires_at": { "type": [ "string", "null" ], "minLength": 0, "maxLength": 1048576, "description": "When the OAuth access token expires, as an RFC 3339 timestamp, if known." }, "refresh": { "anyOf": [ { "$ref": "#/$defs/CreateMcpOauthRefreshParam" }, { "type": "null" } ], "description": "Optional refresh configuration for an HTTPS OAuth token endpoint." } }, "required": [ "type", "mcp_server_url", "access_token" ], "additionalProperties": false, "description": "An OAuth credential for an HTTPS MCP destination." }, "CreateVaultCredentialAuthParamStaticBearer": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "static_bearer" ], "default": "static_bearer", "x-stainless-const": true, "description": "The type of the object. Always `static_bearer`." }, "mcp_server_url": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The HTTPS MCP server URL authorized by this credential." }, "token": { "type": "string", "minLength": 0, "maxLength": 1048576, "description": "The bearer token to store. This secret is never returned in credential resources." } }, "required": [ "type", "mcp_server_url", "token" ], "additionalProperties": false, "description": "A bearer token for an MCP server, without automatic OAuth refresh." }, "VaultCredentialNetworkingParam": { "oneOf": [ { "$ref": "#/$defs/VaultCredentialNetworkingParamUnrestricted" }, { "$ref": "#/$defs/VaultCredentialNetworkingParamLimited" } ], "x-oai-discriminator-values": [ "unrestricted", "limited" ], "description": "Destination permissions for an environment-variable credential. These do not grant network access to the environment." }, "VaultCredentialNetworkingParamLimited": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "limited" ], "default": "limited", "x-stainless-const": true, "description": "The type of the object. Always `limited`." }, "allowed_hosts": { "type": "array", "items": { "type": "string", "minLength": 0, "maxLength": 1048576 }, "minItems": 1, "maxItems": 16, "description": "The 1 to 16 distinct allowed hostnames or IPv4 addresses, normalized to lowercase. Entries contain no scheme, path, port, or wildcard. IPv6 addresses are not supported." } }, "required": [ "type", "allowed_hosts" ], "additionalProperties": false, "description": "Allows substitution only for the listed hosts. The environment network policy must also allow these hosts." }, "VaultCredentialNetworkingParamUnrestricted": { "type": "object", "properties": { "type": { "type": "string", "enum": [ "unrestricted" ], "default": "unrestricted", "x-stainless-const": true, "description": "The type of the object. Always `unrestricted`." } }, "required": [ "type" ], "additionalProperties": false, "description": "Allows substitution for destinations permitted by the environment network policy. Requires `environment.network.access` to be `restricted`, with explicit `allowed_domains`." } } }