text/plain or text/xml depending on the model, not JSON. Errors are the usual JSON error body.ab********yz), and so is any user:password@ in a URL. Usernames, line keys and every other setting are shown as rendered. A Super User can send include-secrets=yes to get the file unmasked; the reveal is audit-logged. Any other scope that sends it gets 403.409 instead of reading:global-one-time-pass is yes). Reading the file would use it up;404.Authorization: Bearer ********************include-secrets=yes.curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/domains/example.com/phones/482567306f13/config?file=poly-482567306f13.cfg&include-secrets=no' \
--header 'Authorization: Bearer <token>'account.1.enable = 1
account.1.user_name = 1001a
account.1.password = s3********99
account.1.sip_server.1.address = core1.example.com