You only do this once per account. After that you query the source like any
other endpoint: nothing extra in the request.
How it fits together
The API that receives your credentials can store them but cannot read them. Only the isolated service that signs in to the source can open them, and only for the query that needs them.1. Register a connection
authorized: true records that you own the account or have its owner’s
authorization. The answer never includes the credentials, only a masked name.
2. Query
- Picking. Croma prefers the connection whose session is already open, then
the one with the most allowance left. Send
connection_idto use a specific one. - One query per account at a time. Queries on different accounts run in parallel; queries on the same account wait their turn, so they never sign in over each other.
- Rotation. When an account reaches its daily allowance, the same query moves to your next connection. Register more than one for more capacity.
Connection states
GET /pe/sunarp/connections/v1 shows each connection’s state, the sign-ins
used today and when it resets.
Security
- Credentials are encrypted as soon as they reach Croma and bound to your organization: they cannot be used by anyone else’s.
- Only the isolated service that signs in to the source can open them.
- They are never returned by the API or shown to anyone, and never written to logs.
- Deleting a connection destroys it permanently.
From the console
platform.usecroma.com/connections lists your organization’s connections with their state and sign-ins used today, connects new ones and deletes them. What you type there goes from your browser straight to the Croma API and is encrypted on arrival.From an agent (MCP)
The same verbs are tools on the MCP server, one set per source:sunarp_connect, sunarp_list_connections and sunarp_delete_connection, and
the same for dian_muisca. Credentials never pass through the conversation:
the connect tool takes no account details and answers with a secure link to the
console, valid for 30 minutes.
After that the agent queries the source like any other.
SUNARP
Peru’s public registries, signed in with a DNI.
DIAN
A taxpayer’s electronic invoices and third-party reports, signed in with their DIAN account on their own behalf or for a company they represent.