Lease a connected service's stored credential for a local runner (or describe its shape)
connections_lease_credentialReturn THIS company's stored credential for a connected service so a LOCAL script or vendor CLI can act with it - the generic alternative to a bespoke tool per service. Works identically for EVERY connected service (aws, stripe, cloudflare, github, twilio, openai, …): one table, one shape, no per-service code. With describeOnly: true the reply carries only the credential's FIELD NAMES plus masked hints, so a caller can map fields → env vars before running anything; without it the reply also carries values, the field→value map a local runner injects into a child process's environment (the local MCP's shell/script_run do this through their own secrets param, which is the usual way to use this tool). Only the local Connections MCP (a device-code sign-in), a Studio console session or a cnx_live_ key receives values; every assistant session (Claude.ai, ChatGPT, Grok, Gemini, Cursor, Claude Code, any other OAuth client) gets the shape plus valuesWithheld. Reply is {service, instance, accountId, fields[], hints{}, primary} - primary names the field that authenticates - plus values when describeOnly is not set.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| service | Yes | Connected service slug (e.g. aws, stripe, cloudflare, github, twilio). | |
| instance | No | Which connected instance (see connections_accounts). Defaults to 'default'. A 12-digit AWS account id also resolves. | |
| describeOnly | No | true → field NAMES and masked hints only, no values: the shape-only mode for planning which env vars a script needs. |