secret_type that determines its payload structure: login, api_key, key_pair, ssh_key, or other. Login secrets can optionally include a TOTP configuration for two-factor authentication.
Create secret
encrypted_payload field contains the client-side encrypted credential data.
Request body
Request example
JSON
Response (201)
JSON
Error responses
Code examples
List secrets
access rules — the same rows List access returns — so you can render who can read each secret without a per-secret follow-up call. access is empty on create/update responses.
Query parameters
Response (200)
JSON
Code examples
Get secret
encrypted_payload. Use this to fetch the ciphertext for client-side decryption. The response inlines the secret’s access rules, same as the list read.
Path parameters
Response (200)
JSON
Code examples
Update secret
Path parameters
Request body
Request example
JSON
Response (200)
Returns the updated secret object (withoutencrypted_payload).
Code examples
Delete secret
204 No Content on success.
Path parameters
Code examples
Secret object
Secret detail object
Extends the secret object, including itsaccess rules, with the encrypted payload. Returned by the get endpoint.
For the plaintext structure of the
encrypted_payload, see Payload schemas.
