---
# @generated by sylphx-gen 0.1.0 from contracts@f99a9bda63ea35002f40ef41b07b570c1c970750996f232cbfb0ed12313637ab. Do not edit.
title: "Capture credential on an agent"
description: "`agents.agents.capture_credential` (POST /v1/{parent}/agents:capture-credential): Captures an existing grant for one session and purpose; never issues a key."
type: reference
product: agents
summary: "Captures an existing grant for one session and purpose; never issues a key."
updated: 2026-09-28
nav: false
---

Captures an existing grant for one session and purpose; never issues a key.

**Not available yet.** Sylphx Agents is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents:capture-credential`
- **Scope** `agents:sessions`
- **Effect** `write` — a successful call changes state.
- **Collection** [agents](/docs/api/agents)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The environment in which the caller holds the existing grant. Required. |
| `session` | `string` | The prospective or existing session to bind this handle to. Required. |
| `turn` | `int64` | The turn allowed to use the execution credential. Required. |
| `credential` | `string` | The existing caller-owned credential, stored encrypted and never logged. Required. Never returned again. |
| `expires_at` | `timestamp` | The issuer-provided expiry of the captured credential. Required. |
| `allowed_tools` | `string[]` | Pinned tool names allowed to inject this credential. Required. |
| `purpose` | `string` | execution, completion, or runtime; runtime handles never enter the guest. Required. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `handle` | `string` | The opaque handle; it never reveals the captured credential. Output only. Never returned again. |
| `generation` | `int64` | The current fencing generation of the captured handle. Output only. |
| `expires_at` | `timestamp` | The issuer-provided expiry of the captured credential. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents:capture-credential" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"allowed_tools":["…"],"credential":"…","expires_at":{},"purpose":"…","session":"…","turn":1}'
```

**TypeScript**

```ts
const response = await sylphx.agents.agents.captureCredential({ allowedTools: ['…'], credential: '…', expiresAt: {}, parent: 'orgs/acme/projects/shop/envs/production', purpose: '…', session: '…', turn: 1 })
```

**Rust**

```rust
let mut req = sylphx::agents::CaptureCredentialRequest::default();
req.allowed_tools = vec!["…".to_string()];
req.credential = "…".to_string();
req.expires_at = Some(Default::default());
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
req.purpose = "…".to_string();
req.session = "…".to_string();
req.turn = 1;
let response = sx.agents().agents().capture_credential(req).await?;
```

**CLI**

```bash
sylphx agents agents capture-credential orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "agents.agents.capture_credential", "args": {"allowed_tools":["…"],"credential":"…","expires_at":{},"parent":"orgs/acme/projects/shop/envs/production","purpose":"…","session":"…","turn":1} }
```
