Store or replace your provider credential
Change · POST /v1/tenants/{tenant}/providers/{provider_name}/credential · MCP tool set-provider-credential
Stores your API credential for one provider, such as a Hetzner Cloud project API token, so that Tarsana can list, create and delete servers for you. It is stored encrypted for your tenant only, and it is used only when you call an operation that needs it. It is never shown again: the answer gives its fingerprint and the time you stored it. A credential that was already stored is replaced.
Roles that can call it: deployer.
Parameters
| Name | In | Required | Description |
|---|---|---|---|
tenant | path | yes | Your tenant ID |
provider_name | path | yes | The provider's name, for example hetzner |
provider_token | body | yes | Your provider API token. For Hetzner Cloud, use a project API token with read and write access. It is sent in the request body and is never shown again |
Returns
A JSON object with these keys: tenant, provider_name, credential_set, fingerprint, set_at, replaced, guarantee, caller_authenticated.
Example request
curl -X POST https://api.tarsana.io/v1/tenants/acme/providers/hetzner/credential \
-H "X-Tarsana-Access-Token: $ACCESS_TOKEN" \
-H 'X-Tarsana-Tenant: acme' \
-H "Content-Type: application/json" \
--data '{"provider_token": "YOUR-HETZNER-API-TOKEN"}'
Example response
{
"tenant": "acme",
"provider_name": "hetzner",
"credential_set": true,
"fingerprint": "sha256:15dedf1c99544c41",
"set_at": "2026-10-05T02:15:40.551914Z",
"replaced": false,
"guarantee": "namespaces are separated, callers are not authenticated",
"caller_authenticated": false
}
Errors
| Code | HTTP | What it means |
|---|---|---|
invalid_parameter | 400 | A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again. |
no_acting_tenant | 400 | Your request does not say which tenant you are acting for. Send your tenant ID in the X-Tarsana-Tenant header, or with --as on the command line. |
isolation_refused | 403 | This address belongs to a tenant ID you do not have access to. Check the tenant ID in the address and in your request header. |
tenant_refused | 400 | This tenant ID is not allowed, or is not in the expected format. Use a different ID made of lower-case letters, digits, dots, dashes and underscores. |
credentials_not_configured | 503 | Storing provider credentials is not available on this Tarsana deployment. Contact Tarsana support if you need it. |
no_such_provider | 404 | Tarsana does not support a provider with this name. The response lists the providers you can use. |
vault_unavailable | 503 | Your provider credential could not be stored or read, because credential storage is not enabled for your tenant or is not working. Contact Tarsana support. |
unauthenticated | 401 | Your request has no credential, or one that Tarsana does not recognise. Sign in with login, or send a valid access token. |
forbidden | 403 | Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them. |
rate_limited | 429 | You sent too many requests in a short time. Wait for the number of seconds in retry_after_seconds, then try again. |
surface_fault | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |