# Reveal a registration's credentials

> POST /registrations/{registration_id}/credentials/reveal

Source: https://docs.trykintsugi.com/reference/2026-07-21/reveal-a-registration-s-credentials

POST /registrations/{registration_id}/credentials/reveal

Reveal a registration's credentials

Decrypt and return specific stored credentials for a registration. Name the fields to reveal in the request body; each must be one of `username`, `password`, `pin`, `security_questions`, `jurisdictionSpecificFields`. `jurisdictionSpecificFields` returns a map of the registration's decrypted jurisdiction secrets (for example California's CDTFA third-party access code or Idaho's TAP access code), gated to the registration's jurisdiction. A field you do not name, or one with nothing stored, comes back `null`, so the response never confirms which credentials exist beyond what you asked for.

This is a privileged, audited operation: only an owner of the organization (or an API key scoped to it) may call it. The response is never cached (`Cache-Control: no-store`). Returns 404 if the registration does not exist or belongs to an organization your credential cannot access, so the API never confirms an id exists; 403 if your credential may read the organization but is not permitted to reveal credentials.

Category: Registrations

Path parameters:
registration_id (string, required) - The unique identifier of the registration.

Request body:
fields (PublicRegistrationCredentialField[], required) - Which stored credentials to decrypt and return. Each must be one of `username`, `password`, `pin`, `security_questions`, `jurisdictionSpecificFields`; any other value is rejected. A field you do not name comes back `null`, indistinguishable from one with nothing stored.
  allowed values: username, password, pin, security_questions, jurisdictionSpecificFields

Response fields:
username (string) - Decrypted username, when `username` was requested and one is stored. `null` otherwise.
password (string) - Decrypted password, when `password` was requested and one is stored. `null` otherwise.
pin (string) - Decrypted PIN, when `pin` was requested and one is stored. `null` otherwise.
securityQuestions (PublicSecurityQuestion[]) - Decrypted security questions, when `security_questions` was requested and any are stored. `null` otherwise.
  question (string, required) - The security question prompt shown by the jurisdiction portal.
  answer (string, required) - The answer to the security question. Write-only: reveal it through the credentials reveal endpoint.
[truncated, see the reference page]

---

Index of every page: https://docs.trykintsugi.com/llms.txt
