Skip to main content
The encrypted_payload field in a vault secret contains a client-side encrypted JSON object. The plaintext structure depends on the secret_type. This page documents the schema for each type. All encryption and decryption happens client-side using your vault key — the server only ever sees ciphertext.

API key

Stores API keys and tokens.
JSON

Key pair

Stores access key and secret key pairs.
JSON

Login

Stores website or service credentials with optional two-factor authentication.
JSON

TOTP configuration

When a login secret includes a totp field, the SDK can generate time-based one-time passwords (RFC 6238) client-side. The TOTP secret is encrypted alongside the rest of the login payload — the server never sees it. You can parse an otpauth://totp/... URI directly using the SDK’s parse_totp_uri / parseTotpUri helper.

SSH key

Stores SSH key pairs and metadata.
JSON

Other

Freeform data for secrets that don’t fit other types.
JSON