> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orgo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get VNC password

> Get the credentials used to connect to a computer.

Returns the computer's VNC credential and its Desktop API token.

<Warning>
  These values grant direct access to the computer's display, shell, and Desktop API. Treat them as secrets. They can change when a computer is started again from its archive or when a resize reports `connection_rotated`, so fetch them fresh rather than caching them.
</Warning>

## Path parameters

<ParamField path="id" type="string" required>
  Computer UUID. This endpoint accepts the UUID only. Unlike the lifecycle endpoints, it does not resolve an `instance_id`, and passing one returns `500`.
</ParamField>

## Response

<ResponseField name="password" type="string">
  The VNC credential. Use it as the password for a VNC client and as the `token` query parameter on the VNC and terminal WebSockets.
</ResponseField>

<ResponseField name="desktop_api_token" type="string">
  The Bearer token for the computer's Desktop API: `/bash`, `/events`, and the terminal. Usually the same string as `password`, but a computer that carries its own stamped token returns that instead, so send this field rather than reusing `password`.
</ResponseField>

## Access control

Workspace owners and editors can read these values. Viewers cannot obtain control credentials. A workspace-scoped API key can only read them for computers in its own workspace. This endpoint answers every one of these refusals with `401`, not `403`, as listed in [Errors](#errors).

## Example

<CodeGroup>
  ```bash cURL theme={null}
  curl https://www.orgo.ai/api/computers/$COMPUTER_ID/vnc-password \
    -H "Authorization: Bearer $ORGO_API_KEY"
  ```

  ```python Python theme={null}
  import requests

  response = requests.get(
      f"https://www.orgo.ai/api/computers/{computer_id}/vnc-password",
      headers={"Authorization": f"Bearer {api_key}"}
  )

  body = response.json()
  vnc_password = body["password"]
  desktop_api_token = body["desktop_api_token"]
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch(`https://www.orgo.ai/api/computers/${computerId}/vnc-password`, {
    headers: { 'Authorization': `Bearer ${apiKey}` }
  });

  const { password, desktop_api_token: desktopApiToken } = await response.json();
  ```
</CodeGroup>

### Response

```json theme={null}
{
  "password": "0a017c595fa7689753a3",
  "desktop_api_token": "0a017c595fa7689753a3"
}
```

## Usage

* **VNC connections**: pass `password` as the password in any websockify-compatible VNC client, such as noVNC.
* **VNC and terminal WebSockets**: pass `password` as the `token` query parameter (see the [Terminal WebSocket](/api-reference/computers/terminal)).
* **Desktop API through Orgo**: send your API key or `password` as the Bearer token on `https://www.orgo.ai/api/desktops/{instance_id}/proxy/{endpoint}`. Orgo swaps an API key for the computer's credential before forwarding.

<Tip>
  For programmatic control, use the [Computer Actions](/api-reference/computers/click) endpoints instead of VNC. For interactive shell access, use the [Terminal WebSocket](/api-reference/computers/terminal).
</Tip>

## Errors

| Status | Body | When |
| - | - | - |
| `401` | `{ "error": "Invalid API key" }` | The Bearer token starts with `sk_` but is not a known Orgo key. |
| `401` | `{ "error": "Authentication required" }` | No `Authorization` header, or a Bearer token that is not an `sk_` key. |
| `401` | `{ "error": "You do not have access to this workspace." }` | You are not a member of the computer's workspace. |
| `401` | `{ "error": "This workspace is view-only. Ask the owner for write access (workspace_read_only)." }` | You have view-only access to the workspace. |
| `401` | `{ "error": "This API key cannot access this workspace (workspace_scope_mismatch)." }` | The API key is scoped to a different workspace. |
| `401` | `{ "error": "Service temporarily unavailable. …" }` | Orgo could not verify the credential because of a server-side fault. Retry; the key is fine. |
| `402` | `{ "error": "Choose a plan to continue." }` | The computer is a trial computer whose trial has ended. |
| `404` | `{ "error": "Desktop not found" }` | No computer matches the UUID. |
| `404` | `{ "error": "Password not available" }` | The computer has no stored credential yet, such as a record still being provisioned. |
| `500` | `{ "error": "Failed to retrieve password" }` | The lookup or decryption failed, including when `id` is not a UUID. |


## OpenAPI

````yaml GET /computers/{id}/vnc-password
openapi: 3.1.0
info:
  title: Orgo API
  description: >-
    Launch cloud computers that AI agents can control and interact with. Create
    workspaces, provision computers, and control them programmatically.
  version: 2.0.0
  contact:
    name: Orgo Support
    email: spencer@orgo.ai
    url: https://orgo.ai
servers:
  - url: https://www.orgo.ai/api
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Account
    description: >-
      Account capacity: how many computers an account may run, and adding or
      giving back more.
  - name: Clients
    description: >-
      Run Orgo for your clients from your own app: a workspace and scoped key
      each, billed to you or to them.
  - name: Workspaces
    description: Organize computers into named workspaces
  - name: Computers
    description: Provision and manage virtual computers
  - name: Computer Lifecycle
    description: Start, stop, and restart computers
  - name: Computer Actions
    description: Control mouse, keyboard, and execute commands
  - name: Screens
    description: >-
      More than one desktop on a single computer. Each screen is its own X
      server with its own cursor and window manager, so an agent working on one
      cannot disturb another.
  - name: Files
    description: Upload and download files
  - name: Templates
    description: Author, build, and launch reproducible computers from templates
paths:
  /computers/{id}/vnc-password:
    get:
      tags:
        - Computers
      summary: Get VNC password
      description: >-
        Returns the computer's VNC credential and its Desktop API token. Owners
        and editors can read them; view-only members cannot. Accepts the
        computer UUID only.
      operationId: getVncPassword
      parameters:
        - name: id
          in: path
          required: true
          description: Computer ID
          schema:
            type: string
      responses:
        '200':
          description: The computer's credentials
          content:
            application/json:
              schema:
                type: object
                properties:
                  password:
                    type: string
                    description: >-
                      The VNC credential. Also the `token` query parameter on
                      the VNC and terminal WebSockets.
                  desktop_api_token:
                    type: string
                    description: >-
                      Bearer token for the computer's Desktop API. Usually equal
                      to `password`, but a computer with its own stamped token
                      returns that instead, so send this field.
              example:
                password: 0a017c595fa7689753a3
                desktop_api_token: 0a017c595fa7689753a3
        '401':
          $ref: '#/components/responses/UnauthorizedWithAccess'
        '402':
          $ref: '#/components/responses/TrialInactive'
        '404':
          description: >-
            No computer with this UUID, or the computer has no stored credential
            yet.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                no-computer:
                  summary: Unknown computer
                  value:
                    error: Desktop not found
                no-password:
                  summary: No credential yet
                  value:
                    error: Password not available
        '500':
          description: The lookup or decryption failed, including when `id` is not a UUID.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Failed to retrieve password
components:
  responses:
    UnauthorizedWithAccess:
      description: >-
        No usable credential, or an access check failed. This endpoint runs its
        workspace access checks during authentication, so it answers a missing
        membership, view-only access, or a key scoped to another workspace with
        `401`, not `403`. A server-side fault while verifying the credential
        also returns `401`, with a `Service temporarily unavailable` message.
        Retry that one; the key is fine.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            invalid-key:
              summary: The key is not one of yours
              value:
                error: Invalid API key
            no-credential:
              summary: No key and no session
              value:
                error: Authentication required
            no-access:
              summary: Not the owner or a member of the workspace
              value:
                error: You do not have access to this workspace.
            view-only:
              summary: View-only member, and the request changes something
              value:
                error: >-
                  This workspace is view-only. Ask the owner for write access
                  (workspace_read_only).
            scope-mismatch:
              summary: The API key is scoped to another workspace
              value:
                error: >-
                  This API key cannot access this workspace
                  (workspace_scope_mismatch).
            service-unavailable:
              summary: Server-side fault while verifying the credential. Retry.
              value:
                error: >-
                  Service temporarily unavailable. The database is not accepting
                  requests. Retry shortly.
    TrialInactive:
      description: >-
        The computer is a free trial computer whose trial is no longer active,
        or it is paid for by its own subscription or dedicated purchase and that
        payment has lapsed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            trial:
              summary: Trial no longer active
              value:
                error: Choose a plan to continue.
            payment:
              summary: The computer's own payment has lapsed
              value:
                error: Manage this computer’s payment in Account → Usage.
  schemas:
    Error:
      type: object
      description: >-
        The base error body. Every failure carries `error`; individual endpoints
        add the fields named in the schemas below.
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable message.
          example: Access denied
        code:
          type: string
          description: >-
            Machine-readable reason. Present on the failures that define one,
            absent otherwise.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key authentication. Get your key at orgo.ai/workspaces

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.