text/plain or text/xml depending on the model. Errors are the usual JSON error body.ab********yz), and so is any user:password@ in a URL. Usernames, line keys, and every other setting are shown as built. A Super User can send include-secrets=yes to get the file unmasked. The reveal is audit-logged.409 instead:global-one-time-pass is yes), because reading the file would use it up404.Authorization: Bearer ********************text/plain or text/xml depending on the model. Content-Disposition names the file.curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/phones/00005e005301/config?file=poly-00005e005301.cfg&include-secrets=no' \
--header 'Authorization: Bearer <token>'account.1.enable = 1
account.1.user_name = 1001a
account.1.password = s3********99
account.1.sip_server.1.address = core1.example.com