> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentsfleet.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a credential for a declared tool

> Issued at the moment a tool needs one, scoped to what the lease already proved. The body names no workspace. The credential is minted against the lease the caller holds, so a runner cannot ask for material outside its own run. 



## OpenAPI

````yaml https://raw.githubusercontent.com/agentsfleet/agentsfleet/main/public/openapi.json post /v1/runners/me/credentials/mint
openapi: 3.1.0
info:
  title: agentsfleet Control Plane API
  description: API for managing workspaces, fleets, triggers, and runs.
  contact:
    name: agentsfleet
    url: https://agentsfleet.net
  license:
    name: MIT
    identifier: MIT
  version: 1.0.0
servers:
  - url: https://api.agentsfleet.net
    description: Production
security: []
paths:
  /v1/runners/me/credentials/mint:
    post:
      tags:
        - Runners
      summary: Mint a credential for a declared tool
      description: >-
        Issued at the moment a tool needs one, scoped to what the lease already
        proved. The body names no workspace. The credential is minted against
        the lease the caller holds, so a runner cannot ask for material outside
        its own run. 
      operationId: runner_mint_credential
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MintCredentialRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MintCredentialResponse'
        '400':
          description: The request could not be read
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '401':
          description: No credential, or one this route does not accept
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '403':
          description: The credential is good and lacks the capability this route requires
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '413':
          description: The payload is over this route's ceiling
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '429':
          description: The instance is at its ceiling
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '500':
          description: The daemon failed to answer
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '502':
          description: An upstream this route depends on refused
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
        '503':
          description: A dependency this route needs is unreachable
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemBody'
      security:
        - RunnerBearerAuth: []
components:
  schemas:
    MintCredentialRequest:
      type: object
      description: >-
        `POST /v1/runners/me/credentials/mint` request.


        The runner forwards the sandboxed child's ask verbatim. `lease_id` binds
        the

        mint to the lease's workspace SERVER-SIDE — the child never names a

        workspace, so a prompt-injected child cannot mint for another tenant.
        The

        request carries no token.
      required:
        - lease_id
        - integration
      properties:
        integration:
          type: string
          description: Which connected integration to mint for.
        lease_id:
          type: string
          description: The lease the mint is bound to.
        scope:
          type:
            - string
            - 'null'
          description: An integration-specific narrowing the broker may honour.
      additionalProperties: false
    MintCredentialResponse:
      type: object
      description: '`POST /v1/runners/me/credentials/mint` reply.'
      required:
        - token
        - expires_at_ms
      properties:
        expires_at_ms:
          type: integer
          format: int64
          description: >-
            Epoch milliseconds after which it stops working, so the caller
            re-mints

            before expiry rather than on failure.
        token:
          type: string
          description: |-
            The short-lived, workspace-scoped credential. Secret — never logged,
            never echoed into a frame.
      additionalProperties: false
    ProblemBody:
      type: object
      description: The body every refusal carries, under `application/problem+json`.
      required:
        - docs_uri
        - title
        - detail
        - error_code
        - request_id
      properties:
        action_id:
          type:
            - string
            - 'null'
          description: 'On that 409 only: the action the gate held.'
        current_state:
          type:
            - string
            - 'null'
          description: 'On a 409 only: the state that forbade the transition.'
        detail:
          type: string
          description: One sentence on what was refused and why.
        docs_uri:
          type: string
          description: Where the error code is documented.
        error_code:
          type: string
          description: The registry code, stable across releases.
        etag:
          type:
            - string
            - 'null'
          description: >-
            On a 412 only: the resource's current entity tag, to refetch and
            retry.
        gate_id:
          type:
            - string
            - 'null'
          description: 'On an answered approval gate''s 409 only: the gate that was answered.'
        missing_secrets:
          type:
            - array
            - 'null'
          items:
            type: string
          description: 'On a 424 only: the credentials this workspace has yet to store.'
        outcome:
          type:
            - string
            - 'null'
          description: 'On that 409 only: the answer that stands.'
        request_id:
          type: string
          description: The request this refusal answers, for support.
        resolved_at:
          type:
            - integer
            - 'null'
          format: int64
          description: 'On that 409 only: when the standing answer was given.'
        resolved_by:
          type:
            - string
            - 'null'
          description: 'On that 409 only: who gave it.'
        title:
          type: string
          description: A short name for the refusal, safe to show a person.
        user_message:
          type:
            - string
            - 'null'
          description: A curated sentence for end users, where the code has one.
  securitySchemes:
    RunnerBearerAuth:
      type: http
      scheme: bearer
      bearerFormat: agt_r
      description: The opaque agt_r token minted when the runner enrols (POST /v1/runners)

````