Aidp Credentials

by oracle-samples90b42d6c24d4No licenseListed Oct 8, 2026Updated Oct 8, 2026

Manage the AIDP credential store (secrets) — list, get, create, update, delete credentials used by AIDP workflows. Use when the user wants to store/rotate a secret centrally instead of embedding it, or manage connection credentials. Primary engine is the official `aidp` CLI (`aidp credentials …`); the same Preview REST API via `oci raw-request` is the no-CLI fallback. Verify the endpoint live before relying on it.

Instructions onlySecurityDevOps & Cloud
AI-generated overview

Manages AIDP centrally stored credentials and secrets via the aidp CLI or a REST fallback.

What it does
Lists, retrieves, creates, updates and deletes credentials in the AIDP credential store, using the aidp CLI as the primary engine and an OCI raw-request REST call as a no-CLI fallback. It documents the create payload shape for SECRET_TOKEN, VAULT_REFERENCE and SERVICE_ACCOUNT credential types, and requires a live verification call before writes. It produces credential records and persisted request payloads, not secret values in output.
When to use it
Use when a user wants to store or rotate a secret centrally in AIDP instead of embedding it in code, or to manage connection credentials. It is also intended for cases where the credential store endpoint must be verified before relying on it.
Requirements
The aidp CLI with an instance ID, api_key auth, profile and region, or the oci CLI for the raw-request fallback; network access to the AIDP endpoint. No scripts ship with the skill; it is instructions only.

aidp-credentials — credential store (Preview)

Manage centrally-stored AIDP credentials/secrets.

CLI (preferred): aidp credentials <command> --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region <r>

  • aidp credentials list | get | create | update | delete

Fallback (no CLI): same credentialStore REST API via oci raw-request (identical endpoint + auth; see references/oci-raw-request.md).

Preview + verify-first (no-fabrication): credentialStore is Preview and the route exists, but its GET/response shape is TBD. Confirm the working path (default 20240831/dataLakes) with a live aidp credentials list (or GET …/credentials) before asserting success or doing writes; record it in references/rest-endpoint-map.md. Treat the path as UNVERIFIED until a live 2xx returns.

When to use

  • "Store/rotate a secret in AIDP", "manage connection credentials", "stop embedding this secret in code".

Workflow

  1. Verify first: aidp credentials list (CLI) — or a GET …/credentials (REST fallback) — returns 2xx; record the version/prefix.
  2. Read/create/update as asked. Never print secret values; pass secret material in the request body only, never echo it back. Confirm before delete/rotate.
  3. Handle async 202 + etag/if-match per the shared conventions.

Mutating ops (create, update/rotate, delete): persist the body to .aidp/payloads/ and confirm first (references/payloads.md).

Create body — CreateDataLakeCredentialDetails

CLI: aidp credentials create <DATALAKE_OCID> --body <JSON> (CLI README "credentials create"). Top-level envelope (SDK create_data_lake_credential_details.py:51-63):

Field (wire)ReqNotes
displayName✅start with a letter; letters/digits/_ only — no secrets in the name
credentialDescription–purpose summary
type✅discriminator — SECRET_TOKEN | VAULT_REFERENCE | SERVICE_ACCOUNT (…:18-26)
credentialDetails✅nested object whose credentialType must match type (credential_details.py:52-73)

credentialDetails shape per type (subclass models + CLI README "credentials create"):

credentialTypeFields (wire)Source
SECRET_TOKENsecretTokenPair: array of {secretKey, secretValue}secret_token_credential_details.py:38-41, secret_pair.py:35-38
VAULT_REFERENCEsecretId (OCID of an external Vault secret)vault_reference_credential_details.py:38-41
SERVICE_ACCOUNTuserId, fingerprint, tenancy, region, isReadOnly, privateKeyservice_account_credential_details.py:63-71

Example (SECRET_TOKEN) — persist to .aidp/payloads/create-<name>-credential.json and confirm first; the secretValue is the only secret material — pass it in the body, never echo it back:

json
{  "displayName": "github_pat",  "credentialDescription": "GitHub PAT for workspace git",  "type": "SECRET_TOKEN",  "credentialDetails": {    "credentialType": "SECRET_TOKEN",    "secretTokenPair": [ { "secretKey": "token", "secretValue": "<PAT>" } ]  }}

Field names are confirmed (SDK attribute_map + CLI README). The full create round-trip is verify-first: …/credentials GET returned 400 here (Preview, list-shape TBD — references/rest-endpoint-map.md), so confirm a 2xx before relying on the POST.

Fallback (no CLI) — REST endpoints (lake-scoped, Preview)

Live-probed 2026-06-10: GET …/dataLakes/<ocid>/credentials → 400 (route exists, list-shape TBD — needs a param/body); …/workspaces/<ws>/credentials → 404 (so credentials are lake-scoped, not workspace-scoped).

  • GET /dataLakes/<ocid>/credentials — list (400 until the required param/shape is supplied — verify live)
  • POST /dataLakes/<ocid>/credentials — create
  • GET|PUT|DELETE /dataLakes/<ocid>/credentials/{key} — get / update / delete

Base URL: https://aidp.<region>.oci.oraclecloud.com/20240831/dataLakes/<dataLakeOcid>/…

Guardrails

  • Secrets never go into logs, the transcript, or committed files.
  • Destructive ops (delete/rotate) require explicit confirmation.

References

  • references/aidp-cli-map.md · references/payloads.md · references/oci-raw-request.md · references/rest-endpoint-map.md

Source and attribution

Source:oracle-samples/oracle-aidp-samplesinai/claude-code-plugins/oracle-ai-data-platform-workbench-engineer-agent/skills/aidp-credentialsat commit90b42d6

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from oracle-samples/oracle-aidp-samples

Aidp Workspace Admin

oracle-samples

Provision and inspect AIDP DataLake instances and workspaces, including private-network workspaces attached to a customer VCN/subnet. Use when the user wants to create/list/get a workspace or DataLake instance, set up a new (e.g. private) AIDP environment, or replicate a customer setup. Create/delete are guarded — confirm before any provisioning.

Awaiting classificationOct 8, 2026

Aidp Volumes

oracle-samples

Work with AIDP volumes — list volumes, browse files inside a volume, upload/download via the PAR flow, and create directories. Use when the user mentions volumes, needs to stage large/binary files, or move data in/out of a volume (distinct from the workspace filesystem). Control-plane via the official `aidp` CLI.

Awaiting classificationOct 8, 2026

Aidp Verified Queries

oracle-samples

Maintains a repository of validated question-to-Spark-SQL pairs so an agent reuses trusted SQL before writing new queries.

Data & AnalyticsOct 8, 2026

Aidp User Settings

oracle-samples

Manage AIDP DataLake user settings and preferences via the aidp CLI or oci raw-request fallback.

Productivity & WorkflowOct 8, 2026

Aidp Spark Optimization

oracle-samples

Guides Apache Spark 3.5.0 performance tuning: partitions, shuffle, joins, skew, memory, file layout, AQE and Delta Lake.

Data & AnalyticsOct 8, 2026

Aidp Semantic Model

oracle-samples

Maintains a .aidp/semantic.md business-meaning layer defining metrics, joins, synonyms and value dictionaries for NL-to-SQL grounding.

Data & AnalyticsOct 8, 2026