> ## Documentation Index
> Fetch the complete documentation index at: https://docs.01advertising.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit credentials

> Public. Validates the form, verifies the credentials with the provider, stores them sealed, and says where the client goes next.



## OpenAPI

````yaml /api/openapi.json post /v1/connect/{token}/credentials
openapi: 3.1.0
info:
  title: 01Advertising Platform API
  version: 0.1.0
  description: >-
    HTTP API of the 01Advertising Platform: organizations, workspaces, API keys,
    audit logs, and the integrations that connect workspaces to advertising
    systems.


    ## Base URL and versions


    Production is `https://api.01ads.com`. Business endpoints live under `/v1`;
    `/health`, `/version`, and `/openapi.json` are unversioned. Before 1.0,
    breaking changes are made in place under `/v1` and shipped together with the
    Portal and CLI; from 1.0 on, a breaking change becomes a `/v2` sibling.
    Operation ids and schema names are stable identifiers. Local development
    runs at `http://127.0.0.1:3000` (`make api`).


    ## Authentication


    Three ways in, declared as security schemes and on every operation: a
    **session cookie** (browsers, set by the sign-in routes), the same session
    as **`Authorization: Bearer`** (the CLI and scripts), or an
    organization-bound **API key** as `x-api-key` (integrations and automation).
    Operations that declare no security requirement are public; operations that
    list only the two session schemes refuse API keys — administrative and
    account changes stay with people.


    ## Errors


    Every non-2xx answer is `application/problem+json` (RFC 9457): `type`,
    `title`, `status`, `detail`, `instance`, and `requestId`; validation
    failures add `errors: [{ path, message }]`. Browser flows answer 302 with no
    body.


    ## Collections, rate limits, and system administration


    Collections are returned whole; `GET /v1/organizations/{orgSlug}/audit-logs`
    is cursor-paginated (`cursor`, `limit`, `nextCursor`). Sign-in emails and
    sign-ups are limited per client address and per email, invitations created
    through an API key per key, and the public connect flow per address and per
    token: a limited request answers 429 with `Retry-After` in seconds.


    Guides, playbooks, and the embedding walkthrough:
    https://docs.01advertising.com.
  termsOfService: https://www.01advertising.com/legal/terms/
  contact:
    name: 01Advertising API support
    email: support@01advertising.com
    url: https://docs.01advertising.com
  license:
    name: Proprietary
    url: https://www.01advertising.com/legal/terms/
servers:
  - url: https://api.01ads.com
    description: Production
security:
  - bearerAuth: []
  - apiKey: []
tags:
  - name: account
    description: The caller's own profile, sign-up, and the invitations addressed to them
    externalDocs:
      url: https://docs.01advertising.com/guides/account
      description: Account guide
  - name: auth
    description: Sign-in methods, magic links, provider sign-in, sessions, and sign-out
    externalDocs:
      url: https://docs.01advertising.com/guides/auth
      description: Authentication guide
  - name: organizations
    description: Organization membership and invitation management
    externalDocs:
      url: https://docs.01advertising.com/guides/organizations
      description: Organizations guide
  - name: workspaces
    description: 'Workspaces: isolated partitions within an organization'
    externalDocs:
      url: https://docs.01advertising.com/guides/workspaces
      description: Workspaces guide
  - name: api-keys
    description: Programmatic access credentials
    externalDocs:
      url: https://docs.01advertising.com/guides/api-keys
      description: API keys guide
  - name: audit
    description: Organization audit trail (cursor-paginated)
    externalDocs:
      url: https://docs.01advertising.com/guides/audit-logs
      description: Audit log guide
  - name: integrations
    description: Workspace integrations with external advertising systems
    externalDocs:
      url: https://docs.01advertising.com/guides/integrations
      description: Integrations guide
  - name: connect
    description: >-
      The public connect flow a client uses to authorize an integration (no
      session)
    externalDocs:
      url: https://docs.01advertising.com/guides/integrations-embedding
      description: Embedding the connect flow
  - name: infra
    description: Health, build information, and this document
    externalDocs:
      url: https://docs.01advertising.com/guides/api-conventions
      description: API conventions
externalDocs:
  url: https://docs.01advertising.com
  description: Developer documentation
paths:
  /v1/connect/{token}/credentials:
    post:
      tags:
        - connect
      summary: Submit credentials
      description: >-
        Public. Validates the form, verifies the credentials with the provider,
        stores them sealed, and says where the client goes next.
      operationId: submitConnectCredentials
      parameters:
        - schema:
            type: string
            minLength: 1
            maxLength: 128
          required: true
          name: token
          in: path
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectFieldValues'
      responses:
        '200':
          description: The outcome
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectOutcome'
        '400':
          description: Invalid fields, or the provider is not a credentials provider
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                validationFailed:
                  summary: A request that does not match its schema
                  value:
                    type: about:blank
                    title: Validation Failed
                    status: 400
                    detail: The request does not match the expected schema.
                    instance: /v1/organizations/acme-corp/workspaces
                    requestId: 7c1b0c1e-5b7d-4b2a-9f1e-3c2d1a0b9e8f
                    errors:
                      - path: name
                        message: 'Too small: expected string to have >=1 characters'
        '404':
          description: Unknown connect link
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                notFound:
                  summary: Nothing accessible at that path
                  value:
                    type: about:blank
                    title: Not Found
                    status: 404
                    detail: Organization not found.
                    instance: /v1/organizations/no-such-org
                    requestId: a1b2c3d4-9e8f-4d7c-8b6a-5f4e3d2c1b0a
        '409':
          description: The link was already used
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '410':
          description: The connect link expired
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too many requests (see Retry-After)
          headers:
            Retry-After:
              description: Seconds to wait before retrying
              schema:
                type: integer
                minimum: 1
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
      security: []
components:
  schemas:
    ConnectFieldValues:
      type: object
      additionalProperties: {}
      description: >-
        The provider's connect or credentials fields, as entered:
        `connectFields` of GET /v1/integrations/providers/{provider}, described
        per provider by the `<Provider>ConnectFields` schemas
    ConnectOutcome:
      type: object
      properties:
        status:
          type: string
          enum:
            - active
            - error
            - pending
        statusDetail:
          type:
            - string
            - 'null'
        returnUrl:
          type:
            - string
            - 'null'
          description: Where to send the client next; null = show the outcome in place
      required:
        - status
        - statusDetail
        - returnUrl
    Problem:
      type: object
      properties:
        type:
          type: string
          examples:
            - about:blank
        title:
          type: string
          examples:
            - Unauthorized
        status:
          type: integer
          examples:
            - 401
        detail:
          type: string
        instance:
          type: string
          examples:
            - /v1/me
        requestId:
          type: string
        errors:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              message:
                type: string
            required:
              - path
              - message
          description: Field-level problems of a validation failure
      required:
        - type
        - title
        - status
        - instance
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Session token as `Authorization: Bearer` (the CLI and scripts).'
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization-bound API key; accepted on /v1 routes other than
        /v1/auth/*.

````