encrypted_payload field in a vault secret contains a client-side encrypted JSON object. The plaintext structure depends on the secret_type. This page documents the schema for each type.
All encryption and decryption happens client-side using your vault key — the server only ever sees ciphertext.
API key
Stores API keys and tokens.JSON
Key pair
Stores access key and secret key pairs.JSON
Login
Stores website or service credentials with optional two-factor authentication.JSON
TOTP configuration
When a login secret includes atotp field, the SDK can generate time-based one-time passwords (RFC 6238) client-side. The TOTP secret is encrypted alongside the rest of the login payload — the server never sees it.
You can parse an
otpauth://totp/... URI directly using the SDK’s parse_totp_uri / parseTotpUri helper.
SSH key
Stores SSH key pairs and metadata.JSON
Other
Freeform data for secrets that don’t fit other types.JSON

