Credential JSON format
Switchboard's credential layer stores and retrieves JSON blobs via the credential helper protocol. The helpers are opaque — they don't enforce a schema — so the format is a Switchboard convention.
{
"access_token": "gho_abc123...",
"refresh_token": "ghr_def456...",
"expires_at": "2026-06-15T00:00:00Z",
"account_id": "acct_..."
}
access_token(required) — the credential value sent in theAuthorizationheader.refresh_token(optional) — OAuth refresh token, present for refresh-capable auth types.expires_at(optional) — RFC 3339 timestamp of token expiry.nullor absent = unknown.account_id(optional) — provider account identifier, e.g. extracted from an OAuth JWT.
Resolution order
When Switchboard needs a credential for a provider:
- If
auth.type = "none"— no credential needed. - It looks for
agentkit-credential-<helper_name>inPATH(and next to its own binary), then runs<helper> get <identity>. - If the helper isn't found or exits non-zero, it falls back to
AGENTKIT_SWITCHBOARD_<NORMALIZED_IDENTITY>(uppercased, non-alphanumeric chars replaced with_). - If neither produces a value, the provider is unconfigured and excluded from routing.