Skip to main content
A zero-knowledge encrypted credential store for your organization. Store API keys, login credentials, SSH keys, and other secrets — Inkbox never sees the plaintext. All encryption and decryption happens client-side using your vault key. API base URL:

Quick start

Create an account and get your API key from the Inkbox console:

Get API key

Most vault API requests support api-key authentication. Vault deletion is handled separately in the Inkbox Console. See individual endpoint docs for details.

Vault

Only one active vault can exist per organization. After deleting a vault, you can initialize a new one.

Initialize vault

Create a new vault with a primary key and four recovery keysPOST /api/v1/vault/initialize

Get vault info

Get vault metadata including secret and key countsGET /api/v1/vault/info

Unlock vault

Fetch encrypted secrets and wrapped keys for client-side decryptionGET /api/v1/vault/unlock

Delete vault

Delete the vault and all its keys and secretsDELETE /api/v1/vault

Secrets

Create secret

Store a new encrypted secretPOST /api/v1/vault/secrets

List secrets

List all secrets (metadata only, no payloads)GET /api/v1/vault/secrets

Get secret

Get a single secret with its encrypted payloadGET /api/v1/vault/secrets/{secret_id}

Update secret

Update a secret’s name, description, or encrypted payloadPATCH /api/v1/vault/secrets/{secret_id}

Delete secret

Delete a secretDELETE /api/v1/vault/secrets/{secret_id}

Keys

List vault keys

List all vault keys (primary and recovery)GET /api/v1/vault/keys

Replace primary key

Replace the primary vault key using current key or recovery codePUT /api/v1/vault/keys/primary

Revoke vault key

Revoke a vault key by its auth hashDELETE /api/v1/vault/keys/{auth_hash}

Access control

Grant identity access

Grant an agent identity access to a specific secretPOST /api/v1/vault/secrets/{secret_id}/access

List access rules

List all identity access rules for a secretGET /api/v1/vault/secrets/{secret_id}/access

Revoke identity access

Revoke an identity’s access to a secretDELETE /api/v1/vault/secrets/{secret_id}/access/{identity_id}

Initialize vault

Create a new vault for your organization. The request body contains client-generated cryptographic material, so use the SDK or CLI rather than calling this directly — see capabilities/vault. Returns 201 with the new vault_id and related identifiers.

Get vault info

Retrieve metadata about the organization’s active vault.

Response (200)


Unlock vault

Fetch the encrypted vault bundle so the client can decrypt it locally. The response contains the wrapped key material needed to derive the org encryption key, plus encrypted_secrets (same shape as GET /vault/secrets/{secret_id}). Use the SDK or CLI to handle the decryption flow.

Delete vault

Delete the vault and all associated keys and secrets. This is a destructive operation — all vault keys and secrets are permanently inaccessible after deletion. This action is performed in the Inkbox Console. After deletion, the organization can initialize a new vault. The deleted vault does not block creating a new one.

Response

Returns 204 No Content on success.

Where to delete a vault

Delete the vault from the Inkbox Console:

Open Inkbox Console


Additional resources