Paste a key
Generate a provider API key in its dashboard and paste it into fetchbean.
OAuth
Authorize fetchbean on the provider’s consent screen without copying a token.
Agent subscription
Store a Codex, Claude Code, or Antigravity subscription credential for an unattended agent runner.
Connecting from the dashboard
Creating or revoking a provider connection is a dashboard action, not an API-key action. Open Connections, pick the provider, and paste the requested credential or complete the OAuth redirect. fetchbean verifies the credential before saving it.Provider API keys and OAuth tokens are never returned. Agent subscriptions are different by design: an org API key can retrieve an existing credential with
GET /v1/connections/{provider}/credential and update it with POST /v1/connections/{provider}/credential, so an unattended runner can use and refresh the subscription. These credential routes do not create a new connection. See Authentication.Calling a connected provider
Once the connection exists, nothing about your request changes. Route the call throughPOST /v1/run with your fetchbean key and fetchbean injects the stored credential:
credential_required error and is billed zero. Connect the provider and retry.
Finding what a provider needs
Every connectable provider declares its own fields. Most paste-key providers want a singleapi_key, while others need context such as a region or account id. The Connections reference lists them per provider, and GET /v1/connections/providers returns the runtime schema with a kind of byok, oauth, or subscription.
Revoking
Revoke a connection from the same dashboard screen. Revocation takes effect immediately: subsequent calls to that provider fail withcredential_required until you reconnect. Revoking a connection never affects your fetchbean API keys, and revoking an API key never affects your connections.

