> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getmillwork.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Start credential setup

> Start a secure browser step for entering a provider credential. The secret never passes through this API.



## OpenAPI

````yaml /openapi/solverapi.openapi.json post /v1/source-credential-handoffs
openapi: 3.1.0
info:
  description: >-
    Run approved AI models under data, cost, and time limits. A cost limit can
    stop another provider call after recorded spend reaches the limit; it cannot
    reverse a call already in progress. Each finished run returns a receipt
    naming the selected model and provider without including the prompt or model
    output. Use the model catalog for what your organization can run now.
    Provider secrets never appear in API requests or responses. Retry a mutation
    with the same Idempotency-Key and the same request body.
  title: Millwork API
  version: 1.0.0
servers:
  - url: https://api.getmillwork.dev
security: []
tags:
  - description: >-
      Submit work, check its status, cancel it, and read the result. The API
      calls each run an execution.
    name: Runs
  - description: A record of how a run was handled, without prompt or result content.
    name: Receipts
  - description: Models this organization can use now.
    name: Models
  - description: Providers and sign-in methods that can be connected.
    name: Available providers
  - description: Provider accounts connected to this organization.
    name: Provider connections
  - description: >-
      One-time browser steps for connecting a provider without sending its
      secret in an API request.
    name: Secure credential setup
  - description: Exact models and provider routes available through connected accounts.
    name: Provider models
  - description: Create, label, list, and revoke organization API keys.
    name: API keys
  - description: Organization members and invitations.
    name: Members
  - description: Metered usage and quota state.
    name: Usage
  - description: Account, plan and allowance snapshot.
    name: Account
  - description: Checkout, billing portal and billing profile.
    name: Billing
  - description: Webhook endpoints, deliveries and replay.
    name: Webhooks
  - description: Organization-scoped compliance export.
    name: Compliance export
  - description: >-
      Models, agents, and skills Millwork can choose for a run. The API calls
      each one an arm.
    name: Registered options
  - description: >-
      Checks that score output and can stop, retry, or choose another option
      within the request policy.
    name: Output checks
  - description: Routing proposals and their review lifecycle.
    name: Repair proposals
  - description: Aggregate evaluation trend and repair history.
    name: Evaluation
  - description: Publisher and release identity records for supported models.
    name: Model definitions
  - description: >-
      Protected provider-credential references. Secret material never appears in
      this API.
    name: Credential references
  - description: Dashboard browser sign-in, sign-up, session lookup, and sign-out.
    name: Browser access
  - description: Read-only demo session setup.
    name: Demo
  - description: Machine setup and the authenticated organization profile.
    name: Organizations
paths:
  /v1/source-credential-handoffs:
    post:
      tags:
        - Secure credential setup
      summary: Start credential setup
      description: >-
        Start a secure browser step for entering a provider credential. The
        secret never passes through this API.
      operationId: postSourceCredentialHandoffs
      requestBody:
        content:
          application/json:
            schema:
              additionalProperties: false
              properties:
                auth_scheme:
                  enum:
                    - api_key
                    - oauth2
                    - aws_sts_sigv4
                  type: string
                source_id:
                  maxLength: 200
                  minLength: 1
                  type: string
              required:
                - source_id
                - auth_scheme
              type: object
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  auth_scheme:
                    enum:
                      - api_key
                      - oauth2
                      - aws_sts_sigv4
                    type: string
                  completed_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  consumed_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  continue_url:
                    format: uri
                    type: string
                  created_at:
                    format: date-time
                    type: string
                  expired_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  expires_at:
                    format: date-time
                    type: string
                  failed_at:
                    anyOf:
                      - format: date-time
                        type: string
                      - type: 'null'
                  failure_code:
                    anyOf:
                      - enum:
                          - cancelled
                          - broker_error
                        type: string
                      - type: 'null'
                  handoff_intent_id:
                    type: string
                  source_id:
                    type: string
                  state:
                    enum:
                      - pending
                      - completed
                      - failed
                      - expired
                      - consumed
                    type: string
                  updated_at:
                    format: date-time
                    type: string
                required:
                  - handoff_intent_id
                  - source_id
                  - auth_scheme
                  - state
                  - failure_code
                  - expires_at
                  - completed_at
                  - failed_at
                  - expired_at
                  - consumed_at
                  - created_at
                  - updated_at
                  - continue_url
                type: object
          description: Default Response
        4XX:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: >-
            Request failure in RFC 7807 format. The `type` field identifies the
            reason. Validation errors list affected fields. Rate and quota
            errors include `retry_after_s` and the `Retry-After` header.
        5XX:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: >-
            Server failure in RFC 7807 format. The response does not include
            internal error details.
      security:
        - bearerAuth: []
        - sessionCookie: []
components:
  schemas:
    Problem:
      additionalProperties: false
      properties:
        detail:
          description: Short, safe, occurrence-specific description. Never a stack trace.
          type: string
        errors:
          description: Per-field validation failures (validation_failed only).
          items:
            additionalProperties: false
            properties:
              field:
                type: string
              message:
                type: string
            required:
              - field
              - message
            type: object
          type: array
        instance:
          description: Unique id for this occurrence, safe to quote in support requests.
          format: uuid
          type: string
        retry_after_s:
          description: >-
            Seconds to wait before retrying (rate_limited and quota_exceeded
            only; mirrored as the Retry-After header).
          type: integer
        status:
          description: HTTP status code, duplicated in the body per RFC 7807.
          type: integer
        title:
          description: Human-readable summary of the problem type.
          type: string
        type:
          description: Stable URI that identifies the error type.
          format: uri
          type: string
      required:
        - type
        - title
        - status
        - instance
      type: object
  securitySchemes:
    bearerAuth:
      description: Organization API key for application requests.
      scheme: bearer
      type: http
    sessionCookie:
      description: Dashboard browser session. Do not use this credential in an application.
      in: cookie
      name: solverapi_session
      type: apiKey

````