> ## Documentation Index
> Fetch the complete documentation index at: https://docs.alakazam.gg/llms.txt
> Use this file to discover all available pages before exploring further.

# Store a cloud-storage credential for dataset import

> Save an owner-scoped credential used by `source_uri` imports from private buckets. Encrypted at rest (Fernet) and **never echoed back** — the listing is masked by construction. Prefer a presigned/SAS URL where you can: it imports with no stored secret at all.




## OpenAPI

````yaml /forge-api-v1.yaml post /api/workbench/source_creds
openapi: 3.0.3
info:
  title: Alakazam Forge API
  version: '1.0'
  description: |
    The Forge Dataset Workbench API: upload or import robotics datasets,
    audit them, propose and run augmentation campaigns, review, and deliver.
    Served by the Forge workbench service at forge.alakazam.gg (not
    api.alakazam.gg).
servers:
  - url: https://forge.alakazam.gg
    description: Forge (Dataset Workbench)
security: []
tags:
  - name: Dataset Workbench
    description: |
      **Served at `https://forge.alakazam.gg`** (not the main API host). The
      Forge Dataset Workbench is the client surface of the robotics
      data-augmentation service: bring a LeRobot robot dataset, a public
      Hugging Face repo, a resumable chunked upload, or a one-click curated
      sample, and walk one owner-scoped **campaign** through the spine
      Source & Health → Sample → Transform → Run + Verify → Deliver, leaving
      with a verified augmented dataset. Every endpoint requires a **Supabase
      user access token** (`Authorization: Bearer …`, the `UserAuth` scheme);
      a missing or invalid token returns `401`, and another user's campaigns,
      runs, and uploads read as `404`. Errors use the platform envelope
      `{"detail": "…"}`. Nothing bills until **Deliver**, which charges 1
      credit per never-before-billed kept episode from your credits wallet.
  - name: Playground batches
    description: |
      The Forge playground's "describe a change" flow is not a REST surface on
      this host: a described change is submitted as a **scenario batch**
      through the platform (the Supabase RPC `create_scenario_batch`) and its
      progress/results stream back over Supabase realtime on the
      `scenario_batches` table. For the equivalent public REST surface, see
      **Scenario Studio** (`/v1/scenario-batches`).
paths:
  /api/workbench/source_creds:
    servers:
      - url: https://forge.alakazam.gg
        description: Forge (Dataset Workbench)
    post:
      tags:
        - Dataset Workbench
      summary: Store a cloud-storage credential for dataset import
      description: >
        Save an owner-scoped credential used by `source_uri` imports from
        private buckets. Encrypted at rest (Fernet) and **never echoed back** —
        the listing is masked by construction. Prefer a presigned/SAS URL where
        you can: it imports with no stored secret at all.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - provider
                - name
                - payload
              properties:
                provider:
                  type: string
                  enum:
                    - s3
                    - gcs
                    - azure
                    - hf
                name:
                  type: string
                payload:
                  type: object
                  description: >-
                    Provider fields: s3 =
                    access_key_id/secret_access_key/region?/endpoint_url?; gcs =
                    service_account_json; azure = account_name +
                    sas_token|account_key; hf = hf_token. Max 16KB.
      responses:
        '200':
          description: Stored (masked)
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  provider:
                    type: string
                  name:
                    type: string
                  created_at:
                    type: string
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Credential store not configured (SOURCE_CREDS_KEY unset).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - UserAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message.
        errors:
          type: array
          items:
            type: string
          description: Field-level validation errors (e.g. on 422 from POST /v1/worlds).
        schemaVersion:
          type: string
      required:
        - detail
  securitySchemes:
    UserAuth:
      type: http
      scheme: bearer
      description: >
        Either a Supabase user access token (from a password login, or the
        passwordless magic-link flow) or a long-lived `forge_sk_…` API key. Both
        are sent as `Authorization: Bearer <value>` and resolve to the same
        owner, so every endpoint accepts either. Session tokens expire in ~1h;
        API keys do not expire and are the credential for MCP clients, CI, and
        partner integrations.

````