Skip to main content
Managed tools use credentials fetchbean supplies. Tools that act on your account use a connection instead: you connect it once, fetchbean stores the credential encrypted, and from then on you call its tools with your fetchbean key exactly like any other tool. Provider API keys and OAuth tokens are injected server-side and are not returned by the connections API. Connections use one of three credential types:

Paste a key

Generate a provider API key in its dashboard and paste it into fetchbean.

OAuth

Authorize fetchbean on the provider’s consent screen without copying a token.

Agent subscription

Store a Codex, Claude Code, or Antigravity subscription credential for an unattended agent runner.
See Connections for the current list and the exact fields each connection needs.

Connecting from the dashboard

Creating or revoking a provider connection is a dashboard action, not an API-key action. Open Connections, pick the provider, and paste the requested credential or complete the OAuth redirect. fetchbean verifies the credential before saving it.
Provider API keys and OAuth tokens are never returned. Agent subscriptions are different by design: an org API key can retrieve an existing credential with GET /v1/connections/{provider}/credential and update it with POST /v1/connections/{provider}/credential, so an unattended runner can use and refresh the subscription. These credential routes do not create a new connection. See Authentication.

Calling a connected provider

Once the connection exists, nothing about your request changes. Route the call through POST /v1/run with your fetchbean key and fetchbean injects the stored credential:
If you call a connected provider before connecting it, the request fails with a credential_required error and is billed zero. Connect the provider and retry.

Finding what a provider needs

Every connectable provider declares its own fields. Most paste-key providers want a single api_key, while others need context such as a region or account id. The Connections reference lists them per provider, and GET /v1/connections/providers returns the runtime schema with a kind of byok, oauth, or subscription.

Revoking

Revoke a connection from the same dashboard screen. Revocation takes effect immediately: subsequent calls to that provider fail with credential_required until you reconnect. Revoking a connection never affects your fetchbean API keys, and revoking an API key never affects your connections.
Connecting a provider unlocks its registered fetchbean tools. See the per-provider tool counts in Connections, or the full parameter and pricing detail in the catalog.