Decrypt and return specific stored credentials for a registration. Name the fields to reveal in the request body; each must be one of username, password, pin, security_questions, jurisdictionSpecificFields. jurisdictionSpecificFields returns a map of the registration's decrypted jurisdiction secrets (for example California's CDTFA third-party access code or Idaho's TAP access code), gated to the registration's jurisdiction. A field you do not name, or one with nothing stored, comes back null, so the response never confirms which credentials exist beyond what you asked for.
This is a privileged, audited operation: only an owner of the organization (or an API key scoped to it) may call it. The response is never cached (Cache-Control: no-store). Returns 404 if the registration does not exist or belongs to an organization your credential cannot access, so the API never confirms an id exists; 403 if your credential may read the organization but is not permitted to reveal credentials.
Release date, as YYYY-MM-DD. Defaults to 2026-07-21.
Narrow the request to one organization (Organization-Id selector).
Target connection id; resolves to its organization.
Platform entity id; resolves to a connection's organization.
Optional source to disambiguate an Entity-Id.
The unique identifier of the registration.
Which stored credentials to decrypt and return. Each must be one of username, password, pin, security_questions, jurisdictionSpecificFields; any other value is rejected. A field you do not name comes back null, indistinguishable from one with nothing stored.
usernamepasswordpinsecurity_questionsjurisdictionSpecificFieldsDecrypted username, when username was requested and one is stored. null otherwise.
Decrypted password, when password was requested and one is stored. null otherwise.
Decrypted PIN, when pin was requested and one is stored. null otherwise.
Decrypted security questions, when security_questions was requested and any are stored. null otherwise.
Decrypted jurisdiction-specific secrets, keyed by the same names the create endpoint accepts (cdtfaThirdPartyAccessSecurityCode for California, accessCode for Idaho), when jurisdictionSpecificFields is requested and stored. null otherwise, revealing nothing about which secrets exist.
Successful Response
The request was invalid.
Authentication failed or was missing.
The credential is not permitted for this request.
The requested resource was not found.
The request conflicts with existing state.
The request failed validation.