> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vern.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit source credentials

> Resume a run paused at `blocked` with `blocked_reason: "credentials"`. The secrets are stored in a secured vault and never enter the agent thread, the run row, or logs. The target connection is taken from the run's own `credential_request` — a key can only fill the connection the agent asked about. Re-submitting overwrites the stored secret so a rejected credential can be re-entered.



## OpenAPI

````yaml /api-reference/openapi.json post /migrations/{migration_id}/runs/{run_id}/credentials
openapi: 3.1.0
info:
  title: Vern Migration API
  version: 1.0.0
  description: >-
    Run Vern as a headless migration engine. Create a migration, upload a
    customer's files, run the managed agent to generate a preview, then execute
    and export clean data. See the Migration API guides for concepts and
    walkthroughs.
servers:
  - url: https://app.vern.so/api/v1
security:
  - apiKey: []
tags:
  - name: Catalog
    description: Discover the sources and templates you set up in the Vern UI.
  - name: Migrations
    description: Create a migration workspace and upload a customer's files.
  - name: Runs
    description: 'Drive the managed agent: generate, refine, execute, answer, and observe.'
  - name: Export
    description: Download a migration's validated data as CSV.
paths:
  /migrations/{migration_id}/runs/{run_id}/credentials:
    parameters:
      - $ref: '#/components/parameters/MigrationId'
      - $ref: '#/components/parameters/RunId'
    post:
      tags:
        - Runs
      summary: Submit source credentials
      description: >-
        Resume a run paused at `blocked` with `blocked_reason: "credentials"`.
        The secrets are stored in a secured vault and never enter the agent
        thread, the run row, or logs. The target connection is taken from the
        run's own `credential_request` — a key can only fill the connection the
        agent asked about. Re-submitting overwrites the stored secret so a
        rejected credential can be re-entered.
      operationId: submitCredentials
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - credentials
              properties:
                credentials:
                  type: object
                  description: >-
                    Secret values keyed to the request's schema. Must be a
                    non-empty object.
                  additionalProperties: true
                connection_id:
                  type: string
                  format: uuid
                  description: >-
                    Optional guard — if sent, must match the run's
                    credential_request.connection_id.
            example:
              credentials:
                client_id: …
                client_secret: …
                refresh_token: …
      responses:
        '200':
          description: Credentials stored; the run resumed and is running again.
          content:
            application/json:
              schema:
                type: object
                properties:
                  run_id:
                    type: string
                    format: uuid
                  status:
                    type: string
                    example: running
              example:
                run_id: d4c3b2a1-9f8e-47d6-b5a4-c3d2e1f0a9b8
                status: running
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: >-
            The run isn't awaiting credentials (not blocked, or blocked on a
            question), connection_id doesn't match, or there's no active
            credential request yet — retry shortly.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: This run is not awaiting credentials.
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  parameters:
    MigrationId:
      name: migration_id
      in: path
      required: true
      description: The migration ID returned by Create a migration.
      schema:
        type: string
        format: uuid
      example: c0a8012e-4f1b-4d3a-9b2c-7e6f5a4b3c2d
    RunId:
      name: run_id
      in: path
      required: true
      description: The run ID returned by Start a run.
      schema:
        type: string
        format: uuid
      example: d4c3b2a1-9f8e-47d6-b5a4-c3d2e1f0a9b8
  responses:
    BadRequest:
      description: Malformed request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: API key missing, malformed, or revoked.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The referenced resource isn't in your account.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    RateLimited:
      description: Rate limit hit — back off and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Too many requests
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: A human-readable error message.
      required:
        - error
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: Your Vern API key. Create one at Settings → API keys.

````