Tarsana docsDashboard

Check whether your provider credential is stored

Read · GET /v1/tenants/{tenant}/providers/{provider_name}/credential · MCP tool provider-credential

Tells you whether Tarsana holds a credential for your tenant at one provider, its fingerprint, and when you stored it. The fingerprint is sha256: followed by the first 16 hex digits of the SHA-256 of the credential, so you can compute it from your own copy and compare. The credential itself is never returned.

Roles that can call it: viewer, builder, deployer.

Parameters

NameInRequiredDescription
tenantpathyesYour tenant ID
provider_namepathyesThe provider's name, for example hetzner

Returns

A JSON object with these keys: tenant, provider_name, credential_set, fingerprint, set_at, guarantee, caller_authenticated.

Example request

curl https://api.tarsana.io/v1/tenants/acme/providers/hetzner/credential \
  -H "X-Tarsana-Access-Token: $ACCESS_TOKEN" \
  -H 'X-Tarsana-Tenant: acme'

Example response

{
  "tenant": "acme",
  "provider_name": "hetzner",
  "credential_set": true,
  "fingerprint": "sha256:15dedf1c99544c41",
  "set_at": "2026-10-05T02:15:40.551914Z",
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false
}

Errors

CodeHTTPWhat it means
invalid_parameter400A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again.
no_acting_tenant400Your request does not say which tenant you are acting for. Send your tenant ID in the X-Tarsana-Tenant header, or with --as on the command line.
isolation_refused403This address belongs to a tenant ID you do not have access to. Check the tenant ID in the address and in your request header.
tenant_refused400This tenant ID is not allowed, or is not in the expected format. Use a different ID made of lower-case letters, digits, dots, dashes and underscores.
credentials_not_configured503Storing provider credentials is not available on this Tarsana deployment. Contact Tarsana support if you need it.
no_such_provider404Tarsana does not support a provider with this name. The response lists the providers you can use.
vault_unavailable503Your provider credential could not be stored or read, because credential storage is not enabled for your tenant or is not working. Contact Tarsana support.
unauthenticated401Your request has no credential, or one that Tarsana does not recognise. Sign in with login, or send a valid access token.
forbidden403Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them.
rate_limited429You sent too many requests in a short time. Wait for the number of seconds in retry_after_seconds, then try again.
surface_fault500Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening.

View this page as Markdown