> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List connectable providers

> List the providers this deployment's credential custody environment configures, through the standard `data`/`next_page` envelope (`next_page` is always null today). Each row carries the provider name, the deployment-declared custody kind (`oauth`, `api_key`, `bearer`, or deployment-held `mtls`), the scope mode (`fixed` pins the reviewed scope set; `caller_specified` forwards the request's scopes), the exact reviewed scopes when fixed, and a `configured` bit that is false while the custody adapter cannot start setup. The catalog is a derived read over the same integration mapping the setup path consults, so a provider absent here is exactly one the hosted Principal setup flow rejects as not configured. It never returns custody identifiers, mTLS binding names, integration keys, connect tokens, or secret material.

Checkfu support posture: alpha; hosted. Required evidence journey: connection-lifecycle. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json get /v1/connection-providers
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: sessionHandoffs
  - name: sessionCapsules
  - name: sessionTrajectories
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/connection-providers:
    get:
      tags:
        - connections
      summary: List connectable providers
      description: >-
        List the providers this deployment's credential custody environment
        configures, through the standard `data`/`next_page` envelope
        (`next_page` is always null today). Each row carries the provider name,
        the deployment-declared custody kind (`oauth`, `api_key`, `bearer`, or
        deployment-held `mtls`), the scope mode (`fixed` pins the reviewed scope
        set; `caller_specified` forwards the request's scopes), the exact
        reviewed scopes when fixed, and a `configured` bit that is false while
        the custody adapter cannot start setup. The catalog is a derived read
        over the same integration mapping the setup path consults, so a provider
        absent here is exactly one the hosted Principal setup flow rejects as
        not configured. It never returns custody identifiers, mTLS binding
        names, integration keys, connect tokens, or secret material.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        connection-lifecycle. Deployment-specific readiness and the latest
        proven release are available from GET /v1/support/capabilities.
      operationId: connections.listConnectionProviders
      parameters:
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
      responses:
        '200':
          description: A bounded page of providers available through Connection custody.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectionProviderPage'
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - validation.malformed
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#validation-malformed
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    required:
                      - type
                      - message
                      - more
                    additionalProperties: false
                additionalProperties: false
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    ConnectionProviderPage:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/ConnectionProvider'
        next_page:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - data
        - next_page
      additionalProperties: false
      description: A bounded page of providers available through Connection custody.
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    ConnectionProvider:
      type: object
      properties:
        provider:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        custody_kind:
          type: string
          enum:
            - oauth
            - api_key
            - bearer
            - mtls
        scope_mode:
          type: string
          enum:
            - fixed
            - caller_specified
        scopes:
          $ref: '#/components/schemas/ConnectionScopes'
        configured:
          type: boolean
        review:
          $ref: '#/components/schemas/Union_142'
        tool_count:
          anyOf:
            - type: integer
              allOf:
                - minimum: 0
            - type: 'null'
        connect_defaults:
          anyOf:
            - type: object
              properties:
                description:
                  type: string
                  allOf:
                    - maxLength: 16384
                scopes:
                  $ref: '#/components/schemas/Arrays_36'
                egress_rules:
                  type: array
                  items:
                    $ref: '#/components/schemas/EgressRule'
                  allOf:
                    - minItems: 1
                    - maxItems: 32
              required:
                - description
                - scopes
                - egress_rules
              additionalProperties: false
            - type: 'null'
      required:
        - provider
        - custody_kind
        - scope_mode
        - scopes
        - configured
        - review
        - tool_count
        - connect_defaults
      additionalProperties: false
      description: >-
        One provider available through the deployment's Connection custody
        catalog.
    ConnectionScopes:
      type: array
      items:
        $ref: '#/components/schemas/ConnectionScope'
      allOf:
        - maxItems: 256
    Union_142:
      type: string
      enum:
        - curated
        - structural
        - unreviewed
    Arrays_36:
      type: array
      items:
        $ref: '#/components/schemas/ConnectionScope'
      allOf:
        - maxItems: 256
        - minItems: 1
    EgressRule:
      type: object
      properties:
        scheme:
          type: string
          enum:
            - https
        host:
          $ref: '#/components/schemas/PublicHostname'
        port:
          type: integer
          allOf:
            - minimum: 1
              maximum: 65535
        path_prefix:
          $ref: '#/components/schemas/HttpPath'
        methods:
          type: array
          items:
            $ref: '#/components/schemas/HttpMethod'
          allOf:
            - minItems: 1
            - maxItems: 7
        allowed_headers:
          $ref: '#/components/schemas/AllowedEgressHeaders'
      required:
        - scheme
        - host
        - port
        - path_prefix
        - methods
      additionalProperties: false
      description: One reviewed HTTPS destination and bounded method/header authority.
    ConnectionScope:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 512
        - pattern: ^[^\s,]+$
    PublicHostname:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 253
        - pattern: ^[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?$
    HttpPath:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 8192
    HttpMethod:
      type: string
      enum:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
        - HEAD
        - OPTIONS
    AllowedEgressHeaders:
      type: array
      items:
        type: string
        allOf:
          - minLength: 1
          - maxLength: 128
          - pattern: ^[!#$%&'*+.^_`|~0-9A-Za-z-]+$
      allOf:
        - maxItems: 128
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````