> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firedrill.run/llms.txt
> Use this file to discover all available pages before exploring further.

# List user-managed control credentials



## OpenAPI

````yaml /api-reference/openapi.json get /v1/credentials
openapi: 3.1.0
info:
  title: Firedrill Control API
  version: 1.0.0
  description: >-
    The control plane for drills, drill runs, and the worlds they run in. Errors
    always carry the canonical envelope; unsafe operations require an
    Idempotency-Key; long work returns an operation resource.
servers:
  - url: https://api.firedrill.run
security:
  - controlCredential: []
paths:
  /v1/credentials:
    get:
      summary: List user-managed control credentials
      operationId: credentials.list
      parameters:
        - name: projectId
          in: query
          required: false
          schema:
            type: string
            pattern: ^prj_[0-9a-z]{12,32}$
        - name: cursor
          in: query
          required: false
          schema:
            type: string
            minLength: 1
            maxLength: 2048
        - name: limit
          in: query
          required: false
          schema:
            default: 50
            type: integer
            minimum: 1
            maximum: 100
        - name: search
          in: query
          required: false
          schema:
            type: string
            minLength: 1
            maxLength: 200
        - name: kind
          in: query
          required: false
          schema:
            default: all
            type: string
            enum:
              - all
              - developer
              - service
        - name: state
          in: query
          required: false
          schema:
            default: all
            type: string
            enum:
              - all
              - active
              - expired
              - revoked
      responses:
        '200':
          description: Credential page
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CredentialPage'
        default:
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    CredentialPage:
      type: object
      properties:
        items:
          maxItems: 100
          type: array
          items:
            type: object
            properties:
              schemaVersion:
                type: number
                enum:
                  - 1
              credentialId:
                type: string
                pattern: ^cred_[0-9a-z]{12,32}$
              organizationId:
                type: string
                pattern: ^org_[0-9a-z]{12,32}$
              projectId:
                type: string
                pattern: ^prj_[0-9a-z]{12,32}$
              kind:
                type: string
                enum:
                  - browser
                  - device
                  - developer
                  - service
                  - github_oidc
              subjectId:
                type: string
                minLength: 1
                maxLength: 255
              name:
                type: string
                minLength: 1
                maxLength: 100
                pattern: ^[^\r\n\t]+$
              actions:
                minItems: 1
                type: array
                items:
                  type: string
                  enum:
                    - profile.read
                    - profile.manage
                    - organization.read
                    - organization.manage
                    - organization.billing.read
                    - organization.billing.manage
                    - organization.audit.read
                    - organization.evidence.export
                    - organization.members.manage
                    - project.create
                    - project.read
                    - project.manage
                    - project.members.manage
                    - repository.read
                    - repository.connect
                    - repository.sync
                    - build.read
                    - build.publish
                    - environment.read
                    - environment.create
                    - environment.promote
                    - environment.archive
                    - session.read
                    - session.create
                    - session.control
                    - session.destroy
                    - drill.read
                    - drill.run
                    - run.read
                    - run.cancel
                    - run.compare
                    - evidence.read
                    - evidence.delete
                    - evidence.share
                    - evidence.export
                    - evidence.upload
                    - credential.manage
                    - tool.read
                    - tool.publish
                    - authoring.read
                    - authoring.run
                    - authoring.publish
                    - ci.execute
                    - demo.read
                    - demo.manage
              keyPrefix:
                type: string
                minLength: 8
                maxLength: 32
              expiresAtMs:
                type: integer
                minimum: -9007199254740991
                maximum: 9007199254740991
              revokedAtMs:
                type: integer
                minimum: -9007199254740991
                maximum: 9007199254740991
              lastUsedAtMs:
                type: integer
                minimum: -9007199254740991
                maximum: 9007199254740991
              createdAtMs:
                type: integer
                minimum: -9007199254740991
                maximum: 9007199254740991
            required:
              - schemaVersion
              - credentialId
              - organizationId
              - kind
              - subjectId
              - name
              - actions
              - keyPrefix
              - expiresAtMs
              - createdAtMs
            additionalProperties: false
        observedAtMs:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        nextCursor:
          type: string
          minLength: 1
          maxLength: 2048
      required:
        - items
        - observedAtMs
      additionalProperties: false
    ErrorEnvelope:
      type: object
      properties:
        code:
          type: string
          pattern: ^(control|world)\.[A-Z][A-Z0-9]*(_[A-Z0-9]+)*$
        message:
          type: string
          minLength: 1
        correlationId:
          type: string
          minLength: 1
        retryable:
          type: boolean
        retryAfterMs:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
        operationId:
          type: string
        source:
          type: string
          enum:
            - platform
            - simulated_provider
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              code:
                type: string
              message:
                type: string
            required:
              - path
              - code
              - message
            additionalProperties: false
        details:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        evidence:
          type: object
          properties:
            sessionId:
              type: string
            runId:
              type: string
            journalSeq:
              type: integer
              minimum: 0
              maximum: 9007199254740991
            buildHash:
              type: string
          additionalProperties: false
      required:
        - code
        - message
        - correlationId
        - retryable
        - source
      additionalProperties: true
  securitySchemes:
    controlCredential:
      type: http
      scheme: bearer
      description: Opaque control credential

````