Set up credential exchange
Provide your app credentials securely to Embedded workflows for each end user.
Credential exchange gives an Embedded workflow access to your app for a specific end user. The customer connects third-party apps in the SDK modal. When the workflow needs your app's credentials, MindCloud calls an endpoint that your backend owns.
Open Embedded → Credential Exchange in the MindCloud dashboard.
Enter the HTTPS Exchange Endpoint on your backend.
Return the fields required by your embedded app's authentication type. Use the response example shown on the dashboard page.
Use Test Exchange with safe sample values before running a workflow.
MindCloud sends a POST request with integrationId, installationId, externalId, and endUserId. The externalId is the identifier you supplied when you created the end user. Resolve that identity on your backend and return credentials only for the requested customer. Treat the response as a secret.
{
"integrationId": "int_...",
"installationId": "install_...",
"externalId": "customer-123",
"endUserId": "enduser_..."
}For request verification, enable Signing Signature and set a shared secret. MindCloud sends X-Timestamp and X-Signature. The signature is a hex HMAC-SHA256 over timestamp + "\nPOST\n" + fullRequestUrl, using that secret. Verify the timestamp and compare signatures in constant time. The full request URL includes the appended endUserId query parameter.
If the exchange URL contains per-user host variables, send their validated values as metadata in Create an end user. This endpoint is for workflow access to your app; connect-only API integrations do not use credential exchange.