> ## Documentation Index
> Fetch the complete documentation index at: https://developer.communicate.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Obtain an account credential with verified email and password proof

> Provide verified account email and current password to obtain an explicit account credential without cookies or Origin. Uses the existing Better Auth password verification and rate limits. No session cookie is returned. The issuer session is kept server-side and bounds credential validity. The secret is returned once; do not put credentials in command arguments or logs.



## OpenAPI

````yaml https://app.communicate.so/api/v1/openapi/mintlify.json post /account-credentials/bootstrap
openapi: 3.1.0
info:
  title: Communicate Public REST API
  version: 1.1.0
  summary: >-
    Scoped agent chat, account credential lifecycle and workspace bootstrap
    operations.
  description: >-
    Canonical external schema for implemented REST operations. Account
    credentials and application sessions authorize the documented account and
    workspace operations separately from workspace keys. Exchange a workspace
    API-key client ID and secret for a short-lived OAuth access token, or use
    the `ck_` key directly for backward compatibility. `requestId` is optional
    but, when supplied, becomes the idempotency key for retries of the same chat
    input.
servers:
  - url: https://app.communicate.so/api/v1
    description: Canonical external base URL served through the Next.js /api/v1 rewrite.
security:
  - oauth2: []
  - bearerAuth: []
paths:
  /account-credentials/bootstrap:
    post:
      tags:
        - Account credentials
      summary: Obtain an account credential with verified email and password proof
      description: >-
        Provide verified account email and current password to obtain an
        explicit account credential without cookies or Origin. Uses the existing
        Better Auth password verification and rate limits. No session cookie is
        returned. The issuer session is kept server-side and bounds credential
        validity. The secret is returned once; do not put credentials in command
        arguments or logs.
      operationId: bootstrapAccountCredential
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccountCredentialBootstrap'
      responses:
        '201':
          description: Obtain an account credential with verified email and password proof
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountCredentialReceipt'
          headers:
            Cache-Control:
              schema:
                type: string
                const: no-store
        '400':
          description: Invalid request body or pagination.
        '401':
          description: >-
            Session or credential missing, invalid, expired or revoked; fresh
            password proof failed when required.
        '403':
          description: >-
            Email verification, trusted origin or required account scope is
            missing.
        '429':
          description: Per-user list or password proof rate limit exceeded.
        '500':
          description: Unexpected server failure.
        '503':
          description: Identity service or freshly issued session unavailable.
      security: []
components:
  schemas:
    AccountCredentialBootstrap:
      type: object
      properties:
        name:
          type: string
          minLength: 5
          maxLength: 300
        password:
          writeOnly: true
          format: password
          type: string
          minLength: 1
          maxLength: 1024
        scopes:
          minItems: 1
          maxItems: 20
          type: array
          items:
            type: string
            enum:
              - workspaces:read
              - workspaces:write
              - workspaces:manage
              - members:read
              - members:write
              - teams:read
              - teams:write
              - invites:accept
              - agents:read
              - agents:write
              - sources:read
              - sources:write
              - learnings:read
              - learnings:write
              - grill:read
              - grill:write
              - notifications:read
              - notifications:write
              - credentials:read
              - credentials:write
        email:
          type: string
          maxLength: 254
          format: email
          pattern: >-
            ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
      required:
        - name
        - password
        - scopes
        - email
      additionalProperties: false
    AccountCredentialReceipt:
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        name:
          type: string
          minLength: 5
          maxLength: 300
        prefix:
          type: string
        scopes:
          minItems: 1
          maxItems: 20
          type: array
          items:
            type: string
            enum:
              - workspaces:read
              - workspaces:write
              - workspaces:manage
              - members:read
              - members:write
              - teams:read
              - teams:write
              - invites:accept
              - agents:read
              - agents:write
              - sources:read
              - sources:write
              - learnings:read
              - learnings:write
              - grill:read
              - grill:write
              - notifications:read
              - notifications:write
              - credentials:read
              - credentials:write
        expiresAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        token:
          readOnly: true
          description: >-
            One-time credential secret; not present in subsequent metadata
            reads.
          type: string
      required:
        - id
        - name
        - prefix
        - scopes
        - expiresAt
        - token
      additionalProperties: false
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client-credentials tokens bounded by the source API key scope
        ceiling.
      flows:
        clientCredentials:
          tokenUrl: https://app.communicate.so/api/v1/oauth/token
          scopes:
            agents:read: List agents in the authenticated workspace.
            chat:write: Create chat turns with an agent in the authenticated workspace.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: Workspace API key token with the `ck_` prefix.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.