Documentation menu

Reference / REST API

A programmable foundation.

Manage secrets, credentials, certificates, signing operations, device identities, and database leases through the SecretServer REST API.

API origin

https://api.secretserver.io

Most resources live under /api/v1. The directory below shows full paths. Available integrations depend on the deployment and configured backends.

Authenticate

Send an API key or JWT in the Authorization: Bearer header. Create and revoke API keys using /api/v1/api-keys with an account administrator identity. Assign only the scopes required by the application. The current authentication middleware does not accept an X-API-Key header.

curl --fail-with-body \
  'https://api.secretserver.io/api/v1/secrets?limit=20&offset=0' \
  -H "Authorization: Bearer $SS_API_KEY"

Secret listing requires secrets:read and returns metadata in a secrets array plus total, the number returned in that page. The default limit is 100; accepted limits are 1–1000. Values are retrieved separately.

Create and retrieve a secret

Use secrets:write to create a generic secret. Its data is a map of string fields. The optional container ID must identify a container in your account.

POST /api/v1/secrets
Content-Type: application/json
Authorization: Bearer <API_KEY>

{
  "name": "application-config",
  "description": "Application connection settings",
  "data": { "value": "<SECRET_VALUE>" },
  "tags": ["production"]
}

Retrieve generic secrets by name with GET /api/v1/secrets/application-config. For container-based lookup across credential types, use GET /api/v1/s/production/db-password. Keep returned values out of application logs.

Update without losing other fields

Generic secret and JKS updates support partial requests and conditional writes. Read the current resource and retain its ETag; send that value in If-Match on update. A stale write returns a conflict. Confirm server compatibility before using partial updates against an older installation.

PUT /api/v1/secrets/application-config
Authorization: Bearer <API_KEY>
Content-Type: application/json
If-Match: "<ETAG_FROM_GET>"

{ "description": "Updated description" }

Other credential types have their own update semantics. See the client compatibility notes.

History, sharing, and temporary access

Cross-type routes use a singular internal secret type, such as computer_credential, password, or ssh_key, and the resource UUID. These are different from collection paths such as computer-credentials.

GET /api/v1/computer_credential/<UUID>/history
POST /api/v1/computer_credential/<UUID>/shares
{ "shared_with_email": "colleague@example.com", "permission": "read" }

POST /api/v1/computer_credential/<UUID>/temp-access
{ "duration_seconds": 900 }

Use history:read, sharing:manage, and temp-access:create as applicable. Redemption at /api/v1/t/:token authenticates with the temporary token itself; protect the complete URL as a secret.

Protected documents

Upload encrypted PDFs, share expiring access, and control original download and rendered-page printing. See the document API and management guide for endpoints, scopes, and limits.

Handle errors

StatusClient action
400Correct the request fields or pagination.
401Replace expired or invalid credentials.
403Check account, scope, and resource access.
404Check the resource name, ID, type, and account.
409 / 412Re-read the resource before retrying a conditional update.
429Back off; honor Retry-After when provided.
500 / 503Check service health and dependency availability. Retry reads with bounded backoff.

Error bodies commonly include an error field. Preserve HTTP status and request identifiers when troubleshooting. Do not automatically retry signing, lease issuance, or other mutations unless you can establish the first request did not complete.

Build a workflow

OpenAPI downloads

The generated OpenAPI inventory covers every registered path and method, path parameters, and router-level authentication. It is not a complete request/response schema; use the examples and linked implementation when integrating. GraphQL is not registered as an active HTTP route.

Endpoint directory

Registered routes from the server source. Expand an endpoint for router-level access requirements. Resource permissions and deployment configuration may impose additional checks.

322 of 322 endpoints

GET/

APIWelcome

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: APIWelcome

GET/.well-known/acme-challenge/:token

ACMEChallenge

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: ACMEChallenge

GET/api/v1/.well-known/jwks.json

Get Tenant JWKSFor Signing Keys

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetTenantJWKSForSigningKeys

GET/api/v1/:type/:id/history

List Secret History

Authentication: Bearer token

Router scopes: history:read

Handler: ListSecretHistory

GET/api/v1/:type/:id/history-settings

Get History Settings

Authentication: Bearer token

Router scopes: history:read

Handler: GetHistorySettings

PUT/api/v1/:type/:id/history-settings

Update History Settings

Authentication: Bearer token

Router scopes: sharing:manage

Handler: UpdateHistorySettings

GET/api/v1/:type/:id/history/:version

Get Secret Version

Authentication: Bearer token

Router scopes: history:read

Handler: GetSecretVersion

GET/api/v1/:type/:id/shares

List Shares

Authentication: Bearer token

Router scopes: sharing:manage

Handler: ListShares

POST/api/v1/:type/:id/shares

Create Share

Authentication: Bearer token

Router scopes: sharing:manage

Handler: CreateShare

GET/api/v1/:type/:id/temp-access

List Temp Access

Authentication: Bearer token

Router scopes: sharing:manage

Handler: ListTempAccess

POST/api/v1/:type/:id/temp-access

Create Temp Access

Authentication: Bearer token

Router scopes: temp-access:create

Handler: CreateTempAccess

GET/api/v1/admin/audit

Admin Query Audit

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminQueryAudit

GET/api/v1/admin/tenants

Admin List Tenants

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminListTenants

POST/api/v1/admin/tenants

Admin Create Tenant

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminCreateTenant

PATCH/api/v1/admin/tenants/:id/activate

Admin Activate Tenant

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminActivateTenant

PUT/api/v1/admin/tenants/:id/quota

Admin Set Quota

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminSetQuota

PUT/api/v1/admin/tenants/:id/sso

Admin Configure SSO

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminConfigureSSO

PATCH/api/v1/admin/tenants/:id/suspend

Admin Suspend Tenant

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminSuspendTenant

GET/api/v1/admin/tenants/:id/users

Admin List Users

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminListUsers

POST/api/v1/admin/users/reset-password

Admin Reset Password

Authentication: Bearer token + platform operator

Router scopes: admin:*

Handler: AdminResetPassword

POST/api/v1/agent/access/:alias

Agent Request

Authentication: Signed device request

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentRequest

GET/api/v1/agent/identity

Agent Request

Authentication: Signed device request

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentRequest

POST/api/v1/agent/oauth/device

Agent OAuth Start

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentOAuthStart

POST/api/v1/agent/oauth/enroll

Agent OAuth Enroll

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentOAuthEnroll

POST/api/v1/agent/oauth/token

Agent OAuth Token

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentOAuthToken

POST/api/v1/agent/variables/resolve

Agent Request

Authentication: Signed device request

Router scopes: Handler-specific checks; consult the implementation.

Handler: AgentRequest

GET/api/v1/agents/devices

List Agents

Authentication: Bearer token

Router scopes: admin:*

Handler: ListAgents

POST/api/v1/agents/devices

Enroll Agent

Authentication: Bearer token

Router scopes: admin:*

Handler: EnrollAgent

DELETE/api/v1/agents/devices/:id

Revoke Agent

Authentication: Bearer token

Router scopes: admin:*

Handler: RevokeAgent

POST/api/v1/agents/oauth/approve

Agent OAuth Approve

Authentication: Bearer token

Router scopes: agents:approve

Handler: AgentOAuthApprove

POST/api/v1/agents/oauth/review

Agent OAuth Review

Authentication: Bearer token

Router scopes: agents:approve

Handler: AgentOAuthReview

GET/api/v1/agents/profiles

List Agent Profiles

Authentication: Bearer token

Router scopes: admin:*

Handler: ListAgentProfiles

PUT/api/v1/agents/profiles/:id

Put Agent Profile

Authentication: Bearer token

Router scopes: admin:*

Handler: PutAgentProfile

GET/api/v1/api-keys

List APIKeys

Authentication: Bearer token

Router scopes: admin:*

Handler: ListAPIKeys

POST/api/v1/api-keys

Create APIKey

Authentication: Bearer token

Router scopes: admin:*

Handler: CreateAPIKey

DELETE/api/v1/api-keys/:id

Revoke APIKey

Authentication: Bearer token

Router scopes: admin:*

Handler: RevokeAPIKey

GET/api/v1/api-tokens

List APITokens

Authentication: Bearer token

Router scopes: tokens:read

Handler: ListAPITokens

POST/api/v1/api-tokens

Create APIToken

Authentication: Bearer token

Router scopes: tokens:read, tokens:write

Handler: CreateAPIToken

DELETE/api/v1/api-tokens/:id

Delete APIToken

Authentication: Bearer token

Router scopes: tokens:read, tokens:write

Handler: DeleteAPIToken

GET/api/v1/api-tokens/:id

Get APIToken

Authentication: Bearer token

Router scopes: tokens:read

Handler: GetAPIToken

POST/api/v1/api-tokens/:id/rotate

Rotate APIToken

Authentication: Bearer token

Router scopes: tokens:read, tokens:write

Handler: RotateAPIToken

GET/api/v1/audit/logs

Get Audit Logs

Authentication: Bearer token

Router scopes: audit:read

Handler: GetAuditLogs

GET/api/v1/audit/logs/export

Export Audit Logs

Authentication: Bearer token

Router scopes: audit:read

Handler: ExportAuditLogs

GET/api/v1/auth/cli/login

CLILogin

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: CLILogin

POST/api/v1/auth/cli/revoke

CLIRevoke

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: CLIRevoke

POST/api/v1/auth/cli/token

CLIToken

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: CLIToken

GET/api/v1/auth/oauth/.well-known/openid-configuration

OIDCDiscovery

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: OIDCDiscovery

GET/api/v1/auth/oauth/authorize

OAuth Authorize

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: OAuthAuthorize

POST/api/v1/auth/oauth/token

OAuth Token

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: OAuthToken

GET/api/v1/auth/oidc/callback

OIDCCallback

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: OIDCCallback

GET/api/v1/auth/oidc/login

OIDCLogin

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: OIDCLogin

POST/api/v1/auth/oidc/logout

OIDCLogout

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: OIDCLogout

POST/api/v1/auth/refresh

Refresh Token

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: RefreshToken

POST/api/v1/auth/webauthn/authentication/begin

Web Authn Authentication Begin

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnAuthenticationBegin

POST/api/v1/auth/webauthn/authentication/finish

Web Authn Authentication Finish

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnAuthenticationFinish

POST/api/v1/auth/webauthn/registration/begin

Web Authn Registration Begin

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnRegistrationBegin

POST/api/v1/auth/webauthn/registration/finish

Web Authn Registration Finish

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnRegistrationFinish

POST/api/v1/auth/workload/token

Workload Login

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: WorkloadLogin

POST/api/v1/auth/zkp/register

SRPRegister

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: SRPRegister

POST/api/v1/auth/zkp/verify

SRPVerify

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: SRPVerify

POST/api/v1/billing/checkout

Create Checkout Session

Authentication: Bearer token

Router scopes: admin:*

Handler: CreateCheckoutSession

GET/api/v1/billing/pricing

Get Pricing Tiers

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetPricingTiers

POST/api/v1/billing/subscription/cancel

Cancel Subscription

Authentication: Bearer token

Router scopes: admin:*

Handler: CancelSubscription

POST/api/v1/billing/subscription/update

Update Subscription

Authentication: Bearer token

Router scopes: admin:*

Handler: UpdateSubscription

GET/api/v1/certificates

List Certificates

Authentication: Bearer token

Router scopes: certs:read

Handler: ListCertificates

GET/api/v1/certificates/:id

Get Certificate

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetCertificate

GET/api/v1/certificates/:id/download

Download Certificate

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: DownloadCertificate

POST/api/v1/certificates/:id/download

Download Certificate

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: DownloadCertificate

POST/api/v1/certificates/:id/renew

Renew Certificate

Authentication: Bearer token

Router scopes: certs:write

Handler: RenewCertificate

POST/api/v1/certificates/:id/revoke

Revoke Certificate

Authentication: Bearer token

Router scopes: certs:revoke

Handler: RevokeCertificate

POST/api/v1/certificates/enroll

Enroll Certificate

Authentication: Bearer token

Router scopes: certs:write

Handler: EnrollCertificate

GET/api/v1/cli/sync

Sync CLIState

Authentication: Bearer token

Router scopes: admin:*

Handler: SyncCLIState

GET/api/v1/code-signing-keys

List Code Signing Keys

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListCodeSigningKeys

POST/api/v1/code-signing-keys

Create Code Signing Key

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateCodeSigningKey

DELETE/api/v1/code-signing-keys/:id

Delete Code Signing Key

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteCodeSigningKey

GET/api/v1/code-signing-keys/:id

Get Code Signing Key

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetCodeSigningKey

PUT/api/v1/code-signing-keys/:id

Update Code Signing Key

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateCodeSigningKey

GET/api/v1/code-signing-keys/:id/export

Export Code Signing Key

Authentication: Bearer token

Router scopes: credentials:read, export:read

Handler: ExportCodeSigningKey

GET/api/v1/computer-credentials

List Computer Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListComputerCredentials

POST/api/v1/computer-credentials

Create Computer Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateComputerCredential

DELETE/api/v1/computer-credentials/:id

Delete Computer Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteComputerCredential

GET/api/v1/computer-credentials/:id

Get Computer Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetComputerCredential

PUT/api/v1/computer-credentials/:id

Update Computer Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateComputerCredential

GET/api/v1/containers

List Containers

Authentication: Bearer token

Router scopes: containers:read

Handler: ListContainers

POST/api/v1/containers

Create Container

Authentication: Bearer token

Router scopes: containers:read, containers:write

Handler: CreateContainer

DELETE/api/v1/containers/:id

Delete Container

Authentication: Bearer token

Router scopes: containers:read, containers:write

Handler: DeleteContainer

GET/api/v1/containers/:id

Get Container

Authentication: Bearer token

Router scopes: containers:read

Handler: GetContainer

PUT/api/v1/containers/:id

Update Container

Authentication: Bearer token

Router scopes: containers:read, containers:write

Handler: UpdateContainer

GET/api/v1/crypto-wallets

List Crypto Wallets

Authentication: Bearer token

Router scopes: passwords:read

Handler: ListCryptoWallets

POST/api/v1/crypto-wallets

Create Crypto Wallet

Authentication: Bearer token

Router scopes: passwords:read, passwords:write

Handler: CreateCryptoWallet

DELETE/api/v1/crypto-wallets/:id

Delete Crypto Wallet

Authentication: Bearer token

Router scopes: passwords:read, passwords:write

Handler: DeleteCryptoWallet

GET/api/v1/crypto-wallets/:id

Get Crypto Wallet

Authentication: Bearer token

Router scopes: passwords:read

Handler: GetCryptoWallet

PUT/api/v1/crypto-wallets/:id

Update Crypto Wallet

Authentication: Bearer token

Router scopes: passwords:read, passwords:write

Handler: UpdateCryptoWallet

GET/api/v1/crypto/backends

List Crypto Backends

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListCryptoBackends

POST/api/v1/crypto/sign

Sign With Key

Authentication: Bearer token

Router scopes: keys:sign

Handler: SignWithKey

GET/api/v1/crypto/signing-keys

List Signing Keys

Authentication: Bearer token

Router scopes: keys:sign

Handler: ListSigningKeys

DELETE/api/v1/database/leases/:id

Revoke Database Lease

Authentication: Bearer token

Router scopes: database:revoke

Handler: RevokeDatabaseLease

POST/api/v1/database/roles/:id/credentials

Issue Database Credentials

Authentication: Bearer token

Router scopes: database:issue

Handler: IssueDatabaseCredentials

POST/api/v1/database/roles/:id/rotate

Rotate Database Credentials

Authentication: Bearer token

Router scopes: database:rotate

Handler: RotateDatabaseCredentials

GET/api/v1/diagnostics

Get Diagnostics

Authentication: Bearer token

Router scopes: admin:*

Handler: GetDiagnostics

GET/api/v1/diagnostics/auth

Get Auth Diagnostics

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetAuthDiagnostics

POST/api/v1/diagnostics/trace

Trace Diagnostics

Authentication: Bearer token

Router scopes: admin:*

Handler: TraceDiagnostics

GET/api/v1/disk-credentials

List Disk Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListDiskCredentials

POST/api/v1/disk-credentials

Create Disk Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateDiskCredential

DELETE/api/v1/disk-credentials/:id

Delete Disk Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteDiskCredential

GET/api/v1/disk-credentials/:id

Get Disk Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetDiskCredential

PUT/api/v1/disk-credentials/:id

Update Disk Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateDiskCredential

GET/api/v1/documents

List Documents

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ListDocuments

POST/api/v1/documents

Upload Document

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: UploadDocument

GET/api/v1/documents/:id

Get Document

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetDocument

GET/api/v1/documents/:id/download

Download Document

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: DownloadDocument

GET/api/v1/documents/:id/grants

List Document Grants

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ListDocumentGrants

POST/api/v1/documents/:id/grants

Grant Document

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GrantDocument

DELETE/api/v1/documents/:id/grants/:grant

Revoke Document Grant

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: RevokeDocumentGrant

GET/api/v1/documents/:id/pages/:page

Preview Document

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: PreviewDocument

POST/api/v1/escrow/combine

Escrow Combine

Authentication: Bearer token

Router scopes: secrets:read

Handler: EscrowCombine

POST/api/v1/escrow/split

Escrow Split

Authentication: Bearer token

Router scopes: secrets:read

Handler: EscrowSplit

POST/api/v1/export/credential-manager

Export To Credential Manager

Authentication: Bearer token

Router scopes: export:read

Handler: ExportToCredentialManager

POST/api/v1/export/json

Export To JSON

Authentication: Bearer token

Router scopes: export:read

Handler: ExportToJSON

POST/api/v1/export/keychain

Export To Keychain

Authentication: Bearer token

Router scopes: export:read

Handler: ExportToKeychain

POST/api/v1/extraction/db

Extract Secrets

Authentication: Bearer token

Router scopes: extract:run

Handler: ExtractSecrets

GET/api/v1/extraction/jobs/:id

Get Extraction Status

Authentication: Bearer token

Router scopes: extract:run

Handler: GetExtractionStatus

POST/api/v1/generate-material

Generate Material

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateMaterial

GET/api/v1/gpg-keys

List GPGKeys

Authentication: Bearer token

Router scopes: gpg:read

Handler: ListGPGKeys

DELETE/api/v1/gpg-keys/:id

Delete GPGKey

Authentication: Bearer token

Router scopes: gpg:write

Handler: DeleteGPGKey

GET/api/v1/gpg-keys/:id

Get GPGKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetGPGKey

PUT/api/v1/gpg-keys/:id

Update GPGKey

Authentication: Bearer token

Router scopes: gpg:write

Handler: UpdateGPGKey

GET/api/v1/gpg-keys/:id/export

Export GPGKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ExportGPGKey

POST/api/v1/gpg-keys/generate

Generate GPGKey

Authentication: Bearer token

Router scopes: gpg:write

Handler: GenerateGPGKey

POST/api/v1/gpg-keys/import

Import GPGKey

Authentication: Bearer token

Router scopes: gpg:write

Handler: ImportGPGKey

GET/api/v1/integration-providers

List Integration Providers

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListIntegrationProviders

GET/api/v1/integrations

List Integration Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListIntegrationCredentials

POST/api/v1/integrations

Create Integration Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateIntegrationCredential

DELETE/api/v1/integrations/:id

Delete Integration Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteIntegrationCredential

GET/api/v1/integrations/:id

Get Integration Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetIntegrationCredential

PUT/api/v1/integrations/:id

Update Integration Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateIntegrationCredential

POST/api/v1/intelligence/check-breach

Check Breach

Authentication: Bearer token

Router scopes: intelligence:read

Handler: CheckBreach

POST/api/v1/ipfs/fetch

IPFSFetch

Authentication: Bearer token

Router scopes: secrets:read

Handler: IPFSFetch

POST/api/v1/ipfs/store

IPFSStore

Authentication: Bearer token

Router scopes: secrets:write

Handler: IPFSStore

GET/api/v1/jks-keystores

List JKSKeystores

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListJKSKeystores

POST/api/v1/jks-keystores

Create JKSKeystore

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateJKSKeystore

DELETE/api/v1/jks-keystores/:id

Delete JKSKeystore

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteJKSKeystore

GET/api/v1/jks-keystores/:id

Get JKSKeystore

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetJKSKeystore

PUT/api/v1/jks-keystores/:id

Update JKSKeystore

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateJKSKeystore

GET/api/v1/jks-keystores/:id/entries

List JKSEntries

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListJKSEntries

POST/api/v1/jks-keystores/:id/entries

Create JKSEntry

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateJKSEntry

DELETE/api/v1/jks-keystores/:id/entries/:alias

Delete JKSEntry

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: DeleteJKSEntry

GET/api/v1/jks-keystores/:id/export

Export JKSKeystore

Authentication: Bearer token

Router scopes: credentials:read, export:read

Handler: ExportJKSKeystore

GET/api/v1/key-catalog

List Key Catalog

Authentication: Bearer token

Router scopes: secrets:read

Handler: ListKeyCatalog

GET/api/v1/keys/age/:id

Get Age Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetAgeKey

POST/api/v1/keys/age/generate

Generate Age Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateAgeKey

GET/api/v1/keys/dkim/:id

Get DKIMKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetDKIMKey

POST/api/v1/keys/dkim/generate

Generate DKIMKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateDKIMKey

GET/api/v1/keys/jwt-signing/:id

Get JWTSigning Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetJWTSigningKey

POST/api/v1/keys/jwt-signing/generate

Generate JWTSigning Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateJWTSigningKey

GET/api/v1/keys/minisign/:id

Get Minisign Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetMinisignKey

POST/api/v1/keys/minisign/generate

Generate Minisign Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateMinisignKey

GET/api/v1/keys/piv/:id

Get PIVKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetPIVKey

POST/api/v1/keys/piv/generate

Generate PIVKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GeneratePIVKey

GET/api/v1/keys/smime/:id

Get SMIMEKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetSMIMEKey

GET/api/v1/keys/smime/:id/pkcs12

Export SMIMEPKCS12

Authentication: Bearer token

Router scopes: credentials:write, export:read

Handler: ExportSMIMEPKCS12

POST/api/v1/keys/smime/generate

Generate SMIMEKey

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateSMIMEKey

GET/api/v1/keys/wireguard/:id

Get Wire Guard Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GetWireGuardKey

POST/api/v1/keys/wireguard/generate

Generate Wire Guard Key

Authentication: Bearer token

Router scopes: credentials:write

Handler: GenerateWireGuardKey

GET/api/v1/ldap-bind-credentials

List LDAPBind Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListLDAPBindCredentials

POST/api/v1/ldap-bind-credentials

Create LDAPBind Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateLDAPBindCredential

DELETE/api/v1/ldap-bind-credentials/:id

Delete LDAPBind Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteLDAPBindCredential

GET/api/v1/ldap-bind-credentials/:id

Get LDAPBind Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetLDAPBindCredential

PUT/api/v1/ldap-bind-credentials/:id

Update LDAPBind Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateLDAPBindCredential

POST/api/v1/ldap/connections/:id/search

LDAPSearch

Authentication: Bearer token

Router scopes: ldap:use

Handler: LDAPSearch

GET/api/v1/ldap/export

LDAPExport

Authentication: Bearer token

Router scopes: ldap:use

Handler: LDAPExport

POST/api/v1/ldap/import

LDAPImport

Authentication: Bearer token

Router scopes: ldap:use

Handler: LDAPImport

POST/api/v1/mock/configure

Configure Mock

Authentication: Bearer token

Router scopes: admin:*

Handler: ConfigureMock

GET/api/v1/mock/templates/:type

Generate Mock Secret

Authentication: Bearer token

Router scopes: admin:*

Handler: GenerateMockSecret

GET/api/v1/ntlm

List NTLMHashes

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListNTLMHashes

POST/api/v1/ntlm

Create NTLMHash

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateNTLMHash

DELETE/api/v1/ntlm/:id

Delete NTLMHash

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteNTLMHash

GET/api/v1/ntlm/:id

Get NTLMHash

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetNTLMHash

PUT/api/v1/ntlm/:id

Update NTLMHash

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateNTLMHash

GET/api/v1/oidc/clients

List OIDCClients

Authentication: Bearer token

Router scopes: oidc:read

Handler: ListOIDCClients

POST/api/v1/oidc/clients

Create OIDCClient

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: CreateOIDCClient

DELETE/api/v1/oidc/clients/:id

Delete OIDCClient

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: DeleteOIDCClient

GET/api/v1/oidc/clients/:id

Get OIDCClient

Authentication: Bearer token

Router scopes: oidc:read

Handler: GetOIDCClient

PUT/api/v1/oidc/clients/:id

Update OIDCClient

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: UpdateOIDCClient

POST/api/v1/oidc/clients/:id/rotate-secret

Rotate OIDCClient Secret

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: RotateOIDCClientSecret

GET/api/v1/oidc/jwks

List OIDCJWKS

Authentication: Bearer token

Router scopes: oidc:read

Handler: ListOIDCJWKS

POST/api/v1/oidc/jwks

Create OIDCJWK

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: CreateOIDCJWK

GET/api/v1/oidc/jwks/.well-known

Get Tenant JWKS

Authentication: Bearer token

Router scopes: oidc:read

Handler: GetTenantJWKS

DELETE/api/v1/oidc/jwks/:id

Delete OIDCJWK

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: DeleteOIDCJWK

GET/api/v1/oidc/jwks/:id

Get OIDCJWK

Authentication: Bearer token

Router scopes: oidc:read

Handler: GetOIDCJWK

PUT/api/v1/oidc/jwks/:id

Update OIDCJWK

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: UpdateOIDCJWK

GET/api/v1/oidc/tokens

List OIDCTokens

Authentication: Bearer token

Router scopes: oidc:read

Handler: ListOIDCTokens

POST/api/v1/oidc/tokens

Store OIDCToken

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: StoreOIDCToken

DELETE/api/v1/oidc/tokens/:id

Delete OIDCToken

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: DeleteOIDCToken

GET/api/v1/oidc/tokens/:id

Get OIDCToken

Authentication: Bearer token

Router scopes: oidc:read

Handler: GetOIDCToken

POST/api/v1/oidc/tokens/:id/revoke

Revoke OIDCToken

Authentication: Bearer token

Router scopes: oidc:read, oidc:write

Handler: RevokeOIDCToken

GET/api/v1/openssl-keys

List Open SSLKeys

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListOpenSSLKeys

DELETE/api/v1/openssl-keys/:id

Delete Open SSLKey

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteOpenSSLKey

GET/api/v1/openssl-keys/:id

Get Open SSLKey

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetOpenSSLKey

GET/api/v1/openssl-keys/:id/export

Export Open SSLKey

Authentication: Bearer token

Router scopes: credentials:read, export:read

Handler: ExportOpenSSLKey

POST/api/v1/openssl-keys/generate

Generate Open SSLKey

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: GenerateOpenSSLKey

POST/api/v1/openssl-keys/import

Import Open SSLKey

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: ImportOpenSSLKey

GET/api/v1/passwords

List Passwords

Authentication: Bearer token

Router scopes: passwords:read

Handler: ListPasswords

POST/api/v1/passwords

Create Password

Authentication: Bearer token

Router scopes: passwords:write

Handler: CreatePassword

DELETE/api/v1/passwords/:id

Delete Password

Authentication: Bearer token

Router scopes: passwords:write

Handler: DeletePassword

GET/api/v1/passwords/:id

Get Password

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetPassword

PUT/api/v1/passwords/:id

Update Password

Authentication: Bearer token

Router scopes: passwords:write

Handler: UpdatePassword

POST/api/v1/passwords/generate

Generate Password

Authentication: Bearer token

Router scopes: passwords:write

Handler: GeneratePassword

GET/api/v1/quotas

Get Quotas

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetQuotas

GET/api/v1/radius-credentials

List RADIUSCredentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListRADIUSCredentials

POST/api/v1/radius-credentials

Create RADIUSCredential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateRADIUSCredential

DELETE/api/v1/radius-credentials/:id

Delete RADIUSCredential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteRADIUSCredential

GET/api/v1/radius-credentials/:id

Get RADIUSCredential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetRADIUSCredential

PUT/api/v1/radius-credentials/:id

Update RADIUSCredential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateRADIUSCredential

GET/api/v1/root-credentials

List Root Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListRootCredentials

POST/api/v1/root-credentials

Create Root Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateRootCredential

DELETE/api/v1/root-credentials/:id

Delete Root Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteRootCredential

GET/api/v1/root-credentials/:id

Get Root Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetRootCredential

PUT/api/v1/root-credentials/:id

Update Root Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateRootCredential

GET/api/v1/s/:container/:key

Get Secret By Path

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetSecretByPath

GET/api/v1/s/:container/:key/:version

Get Secret By Path

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetSecretByPath

GET/api/v1/saml/assertions

List SAMLAssertions

Authentication: Bearer token

Router scopes: saml:read

Handler: ListSAMLAssertions

POST/api/v1/saml/assertions

Store SAMLAssertion

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: StoreSAMLAssertion

DELETE/api/v1/saml/assertions/:id

Delete SAMLAssertion

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: DeleteSAMLAssertion

GET/api/v1/saml/assertions/:id

Get SAMLAssertion

Authentication: Bearer token

Router scopes: saml:read

Handler: GetSAMLAssertion

POST/api/v1/saml/assertions/check-replay

Consume Assertion Check

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: ConsumeAssertionCheck

GET/api/v1/saml/metadata

List SAMLMetadata

Authentication: Bearer token

Router scopes: saml:read

Handler: ListSAMLMetadata

POST/api/v1/saml/metadata

Create SAMLMetadata

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: CreateSAMLMetadata

DELETE/api/v1/saml/metadata/:id

Delete SAMLMetadata

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: DeleteSAMLMetadata

GET/api/v1/saml/metadata/:id

Get SAMLMetadata

Authentication: Bearer token

Router scopes: saml:read

Handler: GetSAMLMetadata

PUT/api/v1/saml/metadata/:id

Update SAMLMetadata

Authentication: Bearer token

Router scopes: saml:read, saml:write

Handler: UpdateSAMLMetadata

GET/api/v1/saml/metadata/:id/xml

Export SAMLMetadata XML

Authentication: Bearer token

Router scopes: saml:read

Handler: ExportSAMLMetadataXML

POST/api/v1/search/semantic

Semantic Search

Authentication: Bearer token

Router scopes: secrets:read

Handler: SemanticSearch

GET/api/v1/secrets

List Secrets

Authentication: Bearer token

Router scopes: secrets:read

Handler: ListSecrets

POST/api/v1/secrets

Create Secret

Authentication: Bearer token

Router scopes: secrets:write

Handler: CreateSecret

DELETE/api/v1/secrets/:name

Delete Secret

Authentication: Bearer token

Router scopes: secrets:delete

Handler: DeleteSecret

GET/api/v1/secrets/:name

Get Secret

Authentication: Bearer token

Router scopes: secrets:read

Handler: GetSecret

PUT/api/v1/secrets/:name

Update Secret

Authentication: Bearer token

Router scopes: secrets:write

Handler: UpdateSecret

GET/api/v1/service-config

List Service Config Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListServiceConfigCredentials

POST/api/v1/service-config

Create Service Config Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateServiceConfigCredential

DELETE/api/v1/service-config/:id

Delete Service Config Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteServiceConfigCredential

GET/api/v1/service-config/:id

Get Service Config Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetServiceConfigCredential

PUT/api/v1/service-config/:id

Update Service Config Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateServiceConfigCredential

PUT/api/v1/settings

Update Settings

Authentication: Bearer token

Router scopes: settings:write

Handler: UpdateSettings

GET/api/v1/shared-with-me

List Shared With Me

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ListSharedWithMe

DELETE/api/v1/shares/:share_id

Delete Share

Authentication: Bearer token

Router scopes: sharing:manage

Handler: DeleteShare

GET/api/v1/skey-otps

List SKeys

Authentication: Bearer token

Router scopes: secrets:read

Handler: ListSKeys

POST/api/v1/skey-otps

Create SKey

Authentication: Bearer token

Router scopes: secrets:write

Handler: CreateSKey

DELETE/api/v1/skey-otps/:id

Delete SKey

Authentication: Bearer token

Router scopes: secrets:delete

Handler: DeleteSKey

GET/api/v1/skey-otps/:id

Get SKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetSKey

POST/api/v1/skey-otps/:id/verify

Verify SKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: VerifySKey

GET/api/v1/social-credentials

List Social Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListSocialCredentials

POST/api/v1/social-credentials

Create Social Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateSocialCredential

DELETE/api/v1/social-credentials/:id

Delete Social Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteSocialCredential

GET/api/v1/social-credentials/:id

Get Social Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetSocialCredential

PUT/api/v1/social-credentials/:id

Update Social Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateSocialCredential

GET/api/v1/software-licenses

List Software Licenses

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListSoftwareLicenses

POST/api/v1/software-licenses

Create Software License

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateSoftwareLicense

DELETE/api/v1/software-licenses/:id

Delete Software License

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteSoftwareLicense

GET/api/v1/software-licenses/:id

Get Software License

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetSoftwareLicense

PUT/api/v1/software-licenses/:id

Update Software License

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateSoftwareLicense

GET/api/v1/ssh-keys

List SSHKeys

Authentication: Bearer token

Router scopes: ssh:read

Handler: ListSSHKeys

DELETE/api/v1/ssh-keys/:id

Delete SSHKey

Authentication: Bearer token

Router scopes: ssh:write

Handler: DeleteSSHKey

GET/api/v1/ssh-keys/:id

Get SSHKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetSSHKey

PUT/api/v1/ssh-keys/:id

Update SSHKey

Authentication: Bearer token

Router scopes: ssh:write

Handler: UpdateSSHKey

GET/api/v1/ssh-keys/:id/export

Export SSHKey

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ExportSSHKey

POST/api/v1/ssh-keys/generate

Generate SSHKey

Authentication: Bearer token

Router scopes: ssh:write

Handler: GenerateSSHKey

POST/api/v1/ssh-keys/import

Import SSHKey

Authentication: Bearer token

Router scopes: ssh:write

Handler: ImportSSHKey

POST/api/v1/steg/decode

Steg Decode

Authentication: Bearer token

Router scopes: secrets:read

Handler: StegDecode

POST/api/v1/steg/encode

Steg Encode

Authentication: Bearer token

Router scopes: secrets:read

Handler: StegEncode

GET/api/v1/t/:token

Get Share By Token

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetShareByToken

DELETE/api/v1/temp-access/:grant_id

Revoke Temp Access

Authentication: Bearer token

Router scopes: sharing:manage

Handler: RevokeTempAccess

POST/api/v1/timelocks

Create Time Lock

Authentication: Bearer token

Router scopes: secrets:read, secrets:write

Handler: CreateTimeLock

GET/api/v1/timelocks/:id

Get Time Lock

Authentication: Bearer token

Router scopes: secrets:read

Handler: GetTimeLock

GET/api/v1/totp-tokens

List TOTPTokens

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListTOTPTokens

POST/api/v1/totp-tokens

Create TOTPToken

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateTOTPToken

DELETE/api/v1/totp-tokens/:id

Delete TOTPToken

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteTOTPToken

GET/api/v1/totp-tokens/:id

Get TOTPToken

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetTOTPToken

PUT/api/v1/totp-tokens/:id

Update TOTPToken

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateTOTPToken

GET/api/v1/totp-tokens/:id/export

Export To URI

Authentication: Bearer token

Router scopes: credentials:read

Handler: ExportToURI

POST/api/v1/totp-tokens/:id/generate

Generate TOTPCode

Authentication: Bearer token

Router scopes: credentials:read

Handler: GenerateTOTPCode

POST/api/v1/totp-tokens/import

Import From URI

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: ImportFromURI

POST/api/v1/transform/decode

Transform Decode

Authentication: Bearer token

Router scopes: transform:use

Handler: TransformDecode

POST/api/v1/transform/detect

Transform Detect

Authentication: Bearer token

Router scopes: transform:use

Handler: TransformDetect

POST/api/v1/transform/encode

Transform Encode

Authentication: Bearer token

Router scopes: transform:use

Handler: TransformEncode

GET/api/v1/usage

Get Usage

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: GetUsage

GET/api/v1/variables

List Variables

Authentication: Bearer token

Router scopes: variables:read

Handler: ListVariables

DELETE/api/v1/variables/:name

Delete Variable

Authentication: Bearer token

Router scopes: variables:write

Handler: DeleteVariable

GET/api/v1/variables/:name

Get Variable

Authentication: Bearer token

Router scopes: variables:read

Handler: GetVariable

PUT/api/v1/variables/:name

Put Variable

Authentication: Bearer token

Router scopes: variables:write

Handler: PutVariable

POST/api/v1/variables/resolve

Resolve Variables

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: ResolveVariables

GET/api/v1/vpn-credentials

List VPNCredentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListVPNCredentials

POST/api/v1/vpn-credentials

Create VPNCredential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateVPNCredential

DELETE/api/v1/vpn-credentials/:id

Delete VPNCredential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteVPNCredential

GET/api/v1/vpn-credentials/:id

Get VPNCredential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetVPNCredential

PUT/api/v1/vpn-credentials/:id

Update VPNCredential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateVPNCredential

GET/api/v1/webauthn/credentials

Web Authn List Credentials

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnListCredentials

DELETE/api/v1/webauthn/credentials/:id

Web Authn Delete Credential

Authentication: Bearer token

Router scopes: Handler-specific checks; consult the implementation.

Handler: WebAuthnDeleteCredential

GET/api/v1/webhooks

List Webhooks

Authentication: Bearer token

Router scopes: webhooks:manage

Handler: ListWebhooks

POST/api/v1/webhooks

Create Webhook

Authentication: Bearer token

Router scopes: webhooks:manage

Handler: CreateWebhook

GET/api/v1/webhooks/:id/deliveries

List Webhook Deliveries

Authentication: Bearer token

Router scopes: webhooks:manage

Handler: ListWebhookDeliveries

POST/api/v1/webhooks/:id/test

Test Webhook

Authentication: Bearer token

Router scopes: webhooks:manage

Handler: TestWebhook

GET/api/v1/wifi-credentials

List Wifi Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListWifiCredentials

POST/api/v1/wifi-credentials

Create Wifi Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateWifiCredential

DELETE/api/v1/wifi-credentials/:id

Delete Wifi Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteWifiCredential

GET/api/v1/wifi-credentials/:id

Get Wifi Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetWifiCredential

PUT/api/v1/wifi-credentials/:id

Update Wifi Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateWifiCredential

GET/api/v1/windows-credentials

List Windows Credentials

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListWindowsCredentials

POST/api/v1/windows-credentials

Create Windows Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateWindowsCredential

DELETE/api/v1/windows-credentials/:id

Delete Windows Credential

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteWindowsCredential

GET/api/v1/windows-credentials/:id

Get Windows Credential

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetWindowsCredential

PUT/api/v1/windows-credentials/:id

Update Windows Credential

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateWindowsCredential

GET/api/v1/yubikeys

List Yubikeys

Authentication: Bearer token

Router scopes: credentials:read

Handler: ListYubikeys

POST/api/v1/yubikeys

Create Yubikey

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: CreateYubikey

DELETE/api/v1/yubikeys/:id

Delete Yubikey

Authentication: Bearer token

Router scopes: credentials:delete, credentials:read

Handler: DeleteYubikey

GET/api/v1/yubikeys/:id

Get Yubikey

Authentication: Bearer token

Router scopes: credentials:read

Handler: GetYubikey

PUT/api/v1/yubikeys/:id

Update Yubikey

Authentication: Bearer token

Router scopes: credentials:read, credentials:write

Handler: UpdateYubikey

POST/api/v1/yubikeys/:id/validate

Validate Yubikey OTP

Authentication: Bearer token

Router scopes: credentials:read

Handler: ValidateYubikeyOTP

GET/health

Health

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: Health

GET/healthz

Healthz

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: Healthz

GET/ready

Ready

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: Ready

POST/webhooks/stripe

Stripe Webhook

Authentication: Endpoint-specific authentication

Router scopes: Handler-specific checks; consult the implementation.

Handler: StripeWebhook