KintsugiKintsugi

Reveal a registration's credentials

POST/registrations/{registration_id}/credentials/reveal

Decrypt and return specific stored credentials for a registration. Name the fields to reveal in the request body; each must be one of username, password, pin, security_questions, jurisdictionSpecificFields. jurisdictionSpecificFields returns a map of the registration's decrypted jurisdiction secrets (for example California's CDTFA third-party access code or Idaho's TAP access code), gated to the registration's jurisdiction. A field you do not name, or one with nothing stored, comes back null, so the response never confirms which credentials exist beyond what you asked for.

This is a privileged, audited operation: only an owner of the organization (or an API key scoped to it) may call it. The response is never cached (Cache-Control: no-store). Returns 404 if the registration does not exist or belongs to an organization your credential cannot access, so the API never confirms an id exists; 403 if your credential may read the organization but is not permitted to reveal credentials.

Authorization

Api-KeystringRequired

Your secret API key. Include it with every request.

Headers

Api-Versiondate

Release date, as YYYY-MM-DD. Defaults to 2026-07-21.

Organization-Idstring

Narrow the request to one organization (Organization-Id selector).

Connection-Idstring

Target connection id; resolves to its organization.

Entity-Idstring

Platform entity id; resolves to a connection's organization.

Entity-Sourcestring

Optional source to disambiguate an Entity-Id.

Path parameters

registration_idstringRequired

The unique identifier of the registration.

Body

fieldsPublicRegistrationCredentialField[]Required

Which stored credentials to decrypt and return. Each must be one of username, password, pin, security_questions, jurisdictionSpecificFields; any other value is rejected. A field you do not name comes back null, indistinguishable from one with nothing stored.

Available options:usernamepasswordpinsecurity_questionsjurisdictionSpecificFields

Response

usernamestring

Decrypted username, when username was requested and one is stored. null otherwise.

passwordstring

Decrypted password, when password was requested and one is stored. null otherwise.

pinstring

Decrypted PIN, when pin was requested and one is stored. null otherwise.

securityQuestionsPublicSecurityQuestion[]

Decrypted security questions, when security_questions was requested and any are stored. null otherwise.

jurisdictionSpecificFieldsobject

Decrypted jurisdiction-specific secrets, keyed by the same names the create endpoint accepts (cdtfaThirdPartyAccessSecurityCode for California, accessCode for Idaho), when jurisdictionSpecificFields is requested and stored. null otherwise, revealing nothing about which secrets exist.

200

Successful Response

400

The request was invalid.

401

Authentication failed or was missing.

403

The credential is not permitted for this request.

404

The requested resource was not found.

409

The request conflicts with existing state.

422

The request failed validation.

cURL
POST /registrations/{registration_id}/credentials/reveal
-H "Api-Key: ***"
-H "Api-Version: 2026-07-21"
{
"fields": [
"username",
"password"
]
}
Example request
https://api.trykintsugi.com/registrations/{registration_id}/credentials/reveal
Response
{
"username": "Jane Doe",
"password": "********",
"pin": "pin",
"securityQuestions": [
{
"question": "What was the name of your first pet?",
"answer": "Rex"
}
],
"jurisdictionSpecificFields": {}
}
Reveal a registration's credentials (2026-07-21) | Kintsugi API Reference