---
title: "Create Integration Instance Auth Credential"
url: "https://dev-portal.dehaven.org/apis/konnect-service-catalog-1-2-0/versions/5f6559bf-d7ba-429c-95c4-cbf2371e663f/operations/create-integration-instance-auth-credential"
---

> Full API specification: https://dev-portal.dehaven.org/apis/konnect-service-catalog-1-2-0/versions/5f6559bf-d7ba-429c-95c4-cbf2371e663f.md

# Create Integration Instance Auth Credential

`POST` `/integration-instances/{id}/auth-credential`

Operation ID: `create-integration-instance-auth-credential`

Creates an auth credential scoped to the given integration instance. Auth credentials are singleton resources that have a 1-to-1 relationship with an integration instance. An attempt to create subsequent auth credentials for an instance will result in a 409 response.

## Path parameters

- `id` (string, required) - The `id` of the integration instance.

## Request body (required)

Content types: `application/json`

## Responses

- `201` - A response containing an integration instance auth credential.

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.2.0
servers:
  - url: https://us.api.konghq.com/v1
    description: US Region Base URL
  - url: https://eu.api.konghq.com/v1
    description: EU Region Base URL
  - url: https://au.api.konghq.com/v1
    description: AU Region Base URL
  - url: https://me.api.konghq.com/v1
    description: ME Region Base URL
  - url: https://in.api.konghq.com/v1
    description: IN Region Base URL
paths:
  /integration-instances/{id}/auth-credential:
    parameters:
      - schema:
          type: string
          example: 3f51fa25-310a-421d-bd1a-007f859021a3
        name: id
        in: path
        required: true
        description: The `id` of the integration instance.
    post:
      x-speakeasy-entity-operation: IntegrationInstanceAuthCredential#create
      x-unstable: true
      x-internal: true
      summary: Create Integration Instance Auth Credential
      operationId: create-integration-instance-auth-credential
      description: >
        Creates an auth credential scoped to the given integration instance.

        Auth credentials are singleton resources that have a 1-to-1 relationship
        with

        an integration instance.


        An attempt to create subsequent auth credentials for an instance will
        result in a 409 response.
      requestBody:
        $ref: "#/components/requestBodies/CreateIntegrationInstanceAuthCredentialReques\
          t"
      responses:
        "201":
          $ref: "#/components/responses/IntegrationInstanceAuthCredentialResponse"
      tags:
        - Integration Instance Auth Credentials
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  requestBodies:
    CreateIntegrationInstanceAuthCredentialRequest:
      required: true
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/CreateIntegrationInstanceAuthCredential"
  responses:
    IntegrationInstanceAuthCredentialResponse:
      description: A response containing an integration instance auth credential.
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/IntegrationInstanceAuthCredential"
  schemas:
    CreateIntegrationInstanceAuthCredential:
      title: CreateIntegrationInstanceAuthCredential
      oneOf:
        - $ref: "#/components/schemas/CreateOAuthCredential"
        - $ref: "#/components/schemas/CreateGitHubAppInstallationCredential"
        - $ref: "#/components/schemas/CreateMultiKeyAuthCredential"
    IntegrationInstanceAuthCredential:
      title: IntegrationInstanceAuthCredential
      description: Object containing metadata for an integration instance auth credential.
      oneOf:
        - $ref: "#/components/schemas/OAuthCredential"
        - $ref: "#/components/schemas/GitHubAppInstallationCredential"
        - $ref: "#/components/schemas/MultiKeyAuthCredential"
    CreateOAuthCredential:
      type: object
      description: Payload used to create an `OAuth` credential for an integration instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - oauth
        config:
          type: object
          title: CreateOAuthCredentialConfig
          additionalProperties: false
          required:
            - grant_type
            - code
            - redirect_uri
          properties:
            grant_type:
              type: string
              description: The OAuth 2.0 grant type used for authorization (e.g.,
                `authorization_code`).
              enum:
                - authorization_code
            code:
              type: string
              description: The authorization code used to exchange for an access token with
                the identity server.
              example: Yzk5ZDczMzRlNDEwY
            redirect_uri:
              type: string
              format: uri
              description: >
                The redirect URI submitted to the authorization server during
                the authentication request 

                to retrieve the authorization code.
              example: https://cloud.konghq.com/us/service-catalog/integrations/pagerduty/oauth
    CreateGitHubAppInstallationCredential:
      type: object
      description: Payload used to create an `GitHub App Installation` credential for
        an integration instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - github_app_installation
        config:
          type: object
          title: CreateGitHubAppInstallationCredentialConfig
          additionalProperties: false
          required:
            - installation_id
            - code
          properties:
            installation_id:
              type: string
              description: The GitHub App installation ID.
              example: "46952218"
            code:
              type: string
              description: The authorization code used to exchange for a GitHub user-scoped
                access token.
              example: Yzk5ZDczMzRlNDEwY
            app_installed_by:
              type: string
              description: The GitHub user who installed the app
    CreateMultiKeyAuthCredential:
      type: object
      description: Payload used to create an `Multi Key` credential for an integration
        instance.
      additionalProperties: false
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - multi_key_auth
        config:
          type: object
          title: CreateMultiKeyAuthCredentialConfig
          additionalProperties: false
          required:
            - headers
          properties:
            headers:
              type: array
              description: >
                A list of header key/value pairs used to transmit API
                credentials to the integration's external API.

                Header names are defined by the integration within its `Multi
                Key` authorization strategy definition.
              items:
                type: object
                required:
                  - name
                  - key
                properties:
                  name:
                    description: Name of the request header
                    type: string
                  key:
                    description: The key used to populate the request header
                    type: string
              example:
                - name: x-api-key
                  key: 9f2a3b4c8d6e7f00112233445566778899aabbccddeeff001122334455667788
    OAuthCredential:
      x-flatten-allOf: true
      allOf:
        - $ref: "#/components/schemas/AuthCredentialBase"
        - type: object
          title: OAuthCredential
          description: Represents a credential scoped to an integration instance that
            supports the `OAuth` authorization strategy.
          required:
            - type
          properties:
            type:
              type: string
              enum:
                - oauth
    GitHubAppInstallationCredential:
      x-flatten-allOf: true
      allOf:
        - $ref: "#/components/schemas/AuthCredentialBase"
        - type: object
          title: GitHubAppInstallationCredential
          description: Represents a credential scoped to an integration instance that
            supports the `GitHub App Installation` authorization strategy.
          required:
            - type
            - config
          properties:
            type:
              type: string
              enum:
                - github_app_installation
            config:
              title: GitHubAppInstallationCredentialConfig
              type: object
              required:
                - installation_id
                - app_installed_by
              properties:
                installation_id:
                  type: string
                  description: The GitHub App installation ID
                app_installed_by:
                  type: string
                  description: The GitHub user who installed the app.
    MultiKeyAuthCredential:
      x-flatten-allOf: true
      allOf:
        - $ref: "#/components/schemas/AuthCredentialBase"
        - type: object
          title: MultiKeyAuthCredential
          description: Represents a credential scoped to an integration instance that
            supports the `Multi Key` authorization strategy.
          required:
            - type
          properties:
            type:
              type: string
              enum:
                - multi_key_auth
    AuthCredentialBase:
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
      properties:
        id:
          $ref: "#/components/schemas/CatalogResourceId"
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at: {}
    CatalogResourceId:
      type: string
      format: base64url
      example: 4UdXnoaDYYJsH_Ir
      description: The resource ID.
      minLength: 16
      maxLength: 16
    IntegrationInstanceRef:
      type: object
      description: Short-hand descriptor of an integration instance.
      required:
        - id
        - name
        - display_name
      properties:
        id:
          type: string
          format: uuid
          example: 772b9caf-ddbc-4f4f-8aa4-8dfbbe420351
          description: The integration instance ID.
        name:
          type: string
          description: >
            The machine name of the integration instance that uniquely
            identifies it within the catalog.
          pattern: ^[0-9a-z.-]+$
          example: aws-lambda-prod
        display_name:
          type: string
          description: The display name of the integration instance.
          example: AWS (prod)
    MissingPermission:
      type: object
      required:
        - scopes
        - message
      properties:
        scopes:
          type: array
          items:
            type: string
            nullable: true
          example:
            - incident:read
        message:
          type: string
          description: >
            Describes the degraded experience of the integration instance due to
            the missing permission.

            May also include a message on how to resolve the missing permission.
```
