Quick start
Create an account and get your API key from the Inkbox console:Get API key
Vault
Only one active vault can exist per organization. After deleting a vault, you can initialize a new one.Initialize vault
Create a new vault with a primary key and four recovery keysPOST
/api/v1/vault/initializeGet vault info
Get vault metadata including secret and key countsGET
/api/v1/vault/infoUnlock vault
Fetch encrypted secrets and wrapped keys for client-side decryptionGET
/api/v1/vault/unlockDelete vault
Delete the vault and all its keys and secretsDELETE
/api/v1/vaultSecrets
Create secret
Store a new encrypted secretPOST
/api/v1/vault/secretsList secrets
List all secrets (metadata only, no payloads)GET
/api/v1/vault/secretsGet secret
Get a single secret with its encrypted payloadGET
/api/v1/vault/secrets/{secret_id}Update secret
Update a secret’s name, description, or encrypted payloadPATCH
/api/v1/vault/secrets/{secret_id}Delete secret
Delete a secretDELETE
/api/v1/vault/secrets/{secret_id}Keys
List vault keys
List all vault keys (primary and recovery)GET
/api/v1/vault/keysReplace primary key
Replace the primary vault key using current key or recovery codePUT
/api/v1/vault/keys/primaryRevoke vault key
Revoke a vault key by its auth hashDELETE
/api/v1/vault/keys/{auth_hash}Access control
Grant identity access
Grant an agent identity access to a specific secretPOST
/api/v1/vault/secrets/{secret_id}/accessList access rules
List all identity access rules for a secretGET
/api/v1/vault/secrets/{secret_id}/accessRevoke identity access
Revoke an identity’s access to a secretDELETE
/api/v1/vault/secrets/{secret_id}/access/{identity_id}Initialize vault
201 with the new vault_id and related identifiers.
Get vault info
Response (200)
Unlock vault
encrypted_secrets (same shape as GET /vault/secrets/{secret_id}). Use the SDK or CLI to handle the decryption flow.
Delete vault
Response
Returns204 No Content on success.

