Create partner credentials
Creates partner credentials for the caller’s organization and returns client_id plus client_secret once. Casa never stores the plaintext secret. Scopes must be a non-empty subset of the public read allowlist (no writes, no read:integrations, no *). Session auth only.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for first-party machines and MCP clients), a partner credential access token (third-party agents; REST-only), a session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. Partner credentials reject X-Property-Id. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Headers
Active organization (property group). Optional cross-check for session (JWT) auth: when sent it must equal the token's verified org_id claim, else 403. The org is taken from the claim, not this header. Ignored for API keys, partner credentials, and static tokens.
Body
Response
Credentials created. client_secret is shown once.