Create an outbound credential
1
Activate Agent Identity
Open the Agent Identity activation page, accept the terms, and activate and authorize.
2
Create the credential
In the console, go to Authentication › Outbound Credentials, create an API Key or OAuth Client for your method, and fill in the credentials (API key, Client ID, Client Secret, callback URL, and so on).
Use it in an agent
Once the credential exists, two wrappers inject it into the agent:VeIdentityFunctionTool for plain function tools and VeIdentityMcpToolset for MCP toolsets. Both take an auth_config — produced by the methods below — and Agent Identity injects the credential at runtime.
Configure the model and create the credential provider in Agent Identity first. The process needs permission to read that provider. Set SERVICE_PROFILE_URL to an HTTPS profile endpoint you control that accepts a Bearer API key. This example reads data without modifying external resources
app.py
API key
The simplest method, for service-to-service calls with fixed credentials. In the console, New › New API Key, fill in a name, the third-party API key, and how it’s passed (Header or Query). Build theauth_config with api_key_auth:
OAuth2 M2M
For service-to-service calls — using tokens with expiry and scopes. In the console, New › New OAuth Client, choose the Machine to Machine (M2M) flow; credentials can use a built-in provider (Lark, Coze, Google, GitHub), an OIDC issuer URL, or fully custom endpoints. Build theauth_config with oauth2_auth and auth_flow="M2M":
OAuth2 user federation
For cases where the app accesses a third-party service on a user’s behalf. In the console, New › New OAuth Client, choose the User Federation (USER_FEDERATION) flow and set the callback URL. Build theauth_config with oauth2_auth and auth_flow="USER_FEDERATION":
Callback address
When configuring the callback in the third-party OAuth2 provider, use the Agent Identity address for your region:- Beijing:
https://auth.id.cn-beijing.volces.com/api/v1/oauth2callback - Shanghai:
https://auth.id.cn-shanghai.volces.com/api/v1/oauth2callback - Guangzhou:
https://auth.id.cn-guangzhou.volces.com/api/v1/oauth2callback
Example
The agent below connects to Volcengine ECS’s MCP service through user-federation auth, querying instances after user authorization:Authentication parameters
VeIdentityFunctionTool requires func and auth_config. into defaults to api_key for API key auth or access_token for OAuth2 and must name a function parameter. The model does not supply that credential parameter; do not return it in tool output
Successful execution returns service data; pending consent may produce an authorization prompt. For failures, check the provider name, region, workload permissions, consent state, and third-party scopes without logging tokens