Skip to main content
A vault secret is an encrypted credential stored in your organization’s vault. The server only stores ciphertext — all encryption and decryption happens client-side using your vault key. Each secret has a secret_type that determines its payload structure: login, api_key, key_pair, ssh_key, or other. Login secrets can optionally include a TOTP configuration for two-factor authentication.

Create secret

Store a new encrypted secret. The encrypted_payload field contains the client-side encrypted credential data.

Request body

Request example

JSON

Response (201)

JSON

Error responses

Code examples


List secrets

List all secrets (metadata only — no encrypted payloads). Optionally filter by secret type. Each secret carries its inlined access rules — the same rows List access returns — so you can render who can read each secret without a per-secret follow-up call. access is empty on create/update responses.

Query parameters

Response (200)

JSON

Code examples


Get secret

Get a single secret including its encrypted_payload. Use this to fetch the ciphertext for client-side decryption. The response inlines the secret’s access rules, same as the list read.

Path parameters

Response (200)

JSON

Code examples


Update secret

Update a secret’s name, description, or encrypted payload. Only supplied fields are modified.

Path parameters

Request body

Request example

JSON

Response (200)

Returns the updated secret object (without encrypted_payload).

Code examples


Delete secret

Delete a secret. Returns 204 No Content on success.

Path parameters

Code examples


Secret object

Secret detail object

Extends the secret object, including its access rules, with the encrypted payload. Returned by the get endpoint. For the plaintext structure of the encrypted_payload, see Payload schemas.