# MCP: credentials

Source: <https://telegafirst.com/docs/mcp-credentials>
Locale: ru
releaseGitSha: c9a428d902de0b479a981e43774f38b9ec077ed7
sourceContentDigest: 41822540fe310c9157f7e275679b0ce6ee4f112573f27ba2cd296a7f52993d0b
Version: 1

# MCP: credentials

Это определения инструментов из текущего ToolRegistry, включая полные inputSchema/outputSchema, scope, required\_scopes (ALL), risk и версию платформы. Наличие определения не означает, что инструмент уже установлен вашим хостом или разрешён вашим credential. Обновляйте tools/list после изменения бизнеса, readiness и прав. Progressive disclosure через load\_domain/describe\_tool и существующий meta-dispatch описаны в [MCP-руководстве](https://telegafirst.com/docs/mcp-guide). [Scopes и права](https://telegafirst.com/docs/scopes-and-permissions) применяются при вызове; risk не заменяет согласие и отдельные требования денежной операции. JSON ниже — схема, а не успешный результат вызова.

## check\_approval

Poll the decision on an issue\_api\_key / scope\_change request by action\_id. On approval the credential is minted and its secret returned ONCE ({status:"approved", credential\_id, secret, token\_prefix}); a re-poll returns {status:"approved"} without the secret. Also returns pending\_approval / denied / expired.

```json
{
  "description": "Poll the decision on an issue_api_key / scope_change request by action_id. On approval the credential is minted and its secret returned ONCE ({status:\"approved\", credential_id, secret, token_prefix}); a re-poll returns {status:\"approved\"} without the secret. Also returns pending_approval / denied / expired.",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "action_id": {
        "description": "Value for action id.",
        "format": "uuid",
        "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
        "type": "string"
      }
    },
    "required": [
      "action_id"
    ],
    "type": "object"
  },
  "name": "check_approval",
  "outputSchema": null,
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:read"
  ],
  "risk": "read",
  "scope": "credentials:read",
  "title": "Check Approval"
}
```

## issue\_api\_key

Request issuance of a new API key with the given scopes. Owner-only. Returns {status:"pending\_approval", action\_id} immediately — the owner confirms in Telegram; then poll check\_approval(action\_id) for the secret.

```json
{
  "description": "Request issuance of a new API key with the given scopes. Owner-only. Returns {status:\"pending_approval\", action_id} immediately — the owner confirms in Telegram; then poll check_approval(action_id) for the secret.",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "bot": {
        "description": "Optional slug of the bot you expect to act on (get_active_bot). If the active bot differs, the call is refused with ACTIVE_BOT_CHANGED and nothing runs.",
        "maxLength": 128,
        "minLength": 1,
        "type": "string"
      },
      "scopes": {
        "description": "Value for scopes.",
        "items": {
          "description": "Value for scopes item.",
          "enum": [
            "onboarding:read",
            "onboarding:write",
            "payments:config",
            "legal:read",
            "legal:write",
            "statuses:read",
            "statuses:write",
            "quick-replies:read",
            "quick-replies:write",
            "team:read",
            "team:write",
            "marketing:read",
            "marketing:write",
            "chains:read",
            "chains:write",
            "events:read",
            "events:write",
            "broadcasts:read",
            "broadcasts:write",
            "agents:read",
            "agents:write",
            "integrations:read",
            "integrations:write",
            "client-config:read",
            "client-config:write",
            "storefront:read",
            "storefront:write",
            "kb:read",
            "kb:write",
            "dialogs:read",
            "dialogs:write",
            "topics:read",
            "topics:write",
            "identity:read",
            "identity:write",
            "credentials:read",
            "credentials:write",
            "domain:read",
            "domain:write",
            "site:read",
            "site:write",
            "support:read",
            "support:write",
            "booking:read",
            "booking:write",
            "partner:read",
            "partner:payout",
            "orders:write",
            "pricing:write",
            "orders:status",
            "analytics:read",
            "sessions",
            "orders",
            "payments",
            "catalog:read",
            "catalog:write",
            "entitlements",
            "push",
            "export",
            "content:read",
            "content:write",
            "pull:form_submissions",
            "push:form_submissions"
          ],
          "type": "string"
        },
        "maxItems": 63,
        "minItems": 1,
        "type": "array"
      }
    },
    "required": [
      "scopes"
    ],
    "type": "object"
  },
  "name": "issue_api_key",
  "outputSchema": null,
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:write"
  ],
  "risk": "write",
  "scope": "credentials:write",
  "title": "Issue Api Key"
}
```

## list\_connections

List this owner session’s MCP connections with their known host, last use, active bot title, Agent Kit freshness, and display token prefix.

```json
{
  "description": "List this owner session’s MCP connections with their known host, last use, active bot title, Agent Kit freshness, and display token prefix.",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {},
    "type": "object"
  },
  "name": "list_connections",
  "outputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "connections": {
        "items": {
          "additionalProperties": false,
          "properties": {
            "active_bot_title": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "host": {
              "type": "string"
            },
            "last_used_at": {
              "anyOf": [
                {
                  "format": "date-time",
                  "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$",
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ]
            },
            "skills_fresh": {
              "type": "boolean"
            },
            "token_prefix": {
              "type": "string"
            }
          },
          "required": [
            "host",
            "last_used_at",
            "active_bot_title",
            "skills_fresh",
            "token_prefix"
          ],
          "type": "object"
        },
        "type": "array"
      }
    },
    "required": [
      "connections"
    ],
    "type": "object"
  },
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:read"
  ],
  "risk": "read",
  "scope": "credentials:read",
  "title": "List Connections"
}
```

## request\_access\_link

Request owner approval for a named desktop client and its owner-mintable MCP scopes. Returns {status:"pending\_approval", action\_id}; poll check\_approval(action\_id) after the owner decides.

```json
{
  "description": "Request owner approval for a named desktop client and its owner-mintable MCP scopes. Returns {status:\"pending_approval\", action_id}; poll check_approval(action_id) after the owner decides.",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "bot": {
        "description": "Optional slug of the bot you expect to act on (get_active_bot). If the active bot differs, the call is refused with ACTIVE_BOT_CHANGED and nothing runs.",
        "maxLength": 128,
        "minLength": 1,
        "type": "string"
      },
      "client_name": {
        "description": "Name of the desktop client requesting owner approval.",
        "maxLength": 120,
        "minLength": 1,
        "type": "string"
      },
      "scopes": {
        "description": "Owner-mintable MCP capabilities requested by the desktop client.",
        "items": {
          "description": "One owner-mintable MCP capability requested by the desktop client.",
          "enum": [
            "onboarding:read",
            "onboarding:write",
            "payments:config",
            "legal:read",
            "legal:write",
            "statuses:read",
            "statuses:write",
            "quick-replies:read",
            "quick-replies:write",
            "team:read",
            "team:write",
            "marketing:read",
            "marketing:write",
            "chains:read",
            "chains:write",
            "events:read",
            "events:write",
            "broadcasts:read",
            "broadcasts:write",
            "agents:read",
            "agents:write",
            "integrations:read",
            "integrations:write",
            "client-config:read",
            "client-config:write",
            "storefront:read",
            "storefront:write",
            "kb:read",
            "kb:write",
            "dialogs:read",
            "dialogs:write",
            "topics:read",
            "topics:write",
            "identity:read",
            "identity:write",
            "credentials:read",
            "credentials:write",
            "domain:read",
            "domain:write",
            "site:read",
            "site:write",
            "support:read",
            "support:write",
            "booking:read",
            "booking:write",
            "partner:read",
            "partner:payout",
            "orders:write",
            "pricing:write",
            "orders:status",
            "analytics:read",
            "sessions",
            "orders",
            "payments",
            "catalog:read",
            "catalog:write",
            "entitlements",
            "push",
            "export",
            "content:read",
            "content:write",
            "pull:form_submissions",
            "push:form_submissions"
          ],
          "type": "string"
        },
        "maxItems": 63,
        "minItems": 1,
        "type": "array"
      }
    },
    "required": [
      "client_name",
      "scopes"
    ],
    "type": "object"
  },
  "name": "request_access_link",
  "outputSchema": null,
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:write"
  ],
  "risk": "write",
  "scope": "credentials:write",
  "title": "Request Access Link"
}
```

## revoke\_connection

Revoke one MCP connection by its display token prefix. Owner-only; it revokes immediately and does not require a second-factor approval.

```json
{
  "description": "Revoke one MCP connection by its display token prefix. Owner-only; it revokes immediately and does not require a second-factor approval.",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "bot": {
        "description": "Optional slug of the bot you expect to act on (get_active_bot). If the active bot differs, the call is refused with ACTIVE_BOT_CHANGED and nothing runs.",
        "maxLength": 128,
        "minLength": 1,
        "type": "string"
      },
      "token_prefix": {
        "description": "Display prefix of the connection token to revoke.",
        "maxLength": 12,
        "minLength": 1,
        "type": "string"
      }
    },
    "required": [
      "token_prefix"
    ],
    "type": "object"
  },
  "name": "revoke_connection",
  "outputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "revoked_at": {
        "format": "date-time",
        "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$",
        "type": "string"
      }
    },
    "required": [
      "revoked_at"
    ],
    "type": "object"
  },
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:write"
  ],
  "risk": "write",
  "scope": "credentials:write",
  "title": "Revoke Connection"
}
```

## scope\_change

Request a scope change for an existing API key (credential\_id). Owner-only. Returns {status:"pending\_approval", action\_id} immediately; the owner confirms in Telegram, then poll check\_approval(action\_id) — on approval the key is re-scoped IN-PLACE (its secret is unchanged).

```json
{
  "description": "Request a scope change for an existing API key (credential_id). Owner-only. Returns {status:\"pending_approval\", action_id} immediately; the owner confirms in Telegram, then poll check_approval(action_id) — on approval the key is re-scoped IN-PLACE (its secret is unchanged).",
  "domain": "credentials",
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "additionalProperties": false,
    "properties": {
      "bot": {
        "description": "Optional slug of the bot you expect to act on (get_active_bot). If the active bot differs, the call is refused with ACTIVE_BOT_CHANGED and nothing runs.",
        "maxLength": 128,
        "minLength": 1,
        "type": "string"
      },
      "credential_id": {
        "description": "Value for credential id.",
        "format": "uuid",
        "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
        "type": "string"
      },
      "scopes": {
        "description": "Value for scopes.",
        "items": {
          "description": "Value for scopes item.",
          "enum": [
            "onboarding:read",
            "onboarding:write",
            "payments:config",
            "legal:read",
            "legal:write",
            "statuses:read",
            "statuses:write",
            "quick-replies:read",
            "quick-replies:write",
            "team:read",
            "team:write",
            "marketing:read",
            "marketing:write",
            "chains:read",
            "chains:write",
            "events:read",
            "events:write",
            "broadcasts:read",
            "broadcasts:write",
            "agents:read",
            "agents:write",
            "integrations:read",
            "integrations:write",
            "client-config:read",
            "client-config:write",
            "storefront:read",
            "storefront:write",
            "kb:read",
            "kb:write",
            "dialogs:read",
            "dialogs:write",
            "topics:read",
            "topics:write",
            "identity:read",
            "identity:write",
            "credentials:read",
            "credentials:write",
            "domain:read",
            "domain:write",
            "site:read",
            "site:write",
            "support:read",
            "support:write",
            "booking:read",
            "booking:write",
            "partner:read",
            "partner:payout",
            "orders:write",
            "pricing:write",
            "orders:status",
            "analytics:read",
            "sessions",
            "orders",
            "payments",
            "catalog:read",
            "catalog:write",
            "entitlements",
            "push",
            "export",
            "content:read",
            "content:write",
            "pull:form_submissions",
            "push:form_submissions"
          ],
          "type": "string"
        },
        "maxItems": 63,
        "minItems": 1,
        "type": "array"
      }
    },
    "required": [
      "credential_id",
      "scopes"
    ],
    "type": "object"
  },
  "name": "scope_change",
  "outputSchema": null,
  "platform_version": "1.0.19",
  "required_scopes": [
    "credentials:write"
  ],
  "risk": "write",
  "scope": "credentials:write",
  "title": "Scope Change"
}
```
