Skip to content
Stackship documentation Svenska

SecretsUsers

API reference

Every HTTP endpoint of the secrets module: authentication, IAM action, parameters, bodies and status codes.

Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.

Docs

GET /docs/secrets/manifest.json

  • Authentication: required
  • Operation name: DocsManifest_secrets

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

GET /docs/secrets/{path}

  • Authentication: required
  • Operation name: DocsFile_secrets

Parameters

Name In Type Required
path path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Secret Vaults

GET /boundaries/{boundaryId}/resources/secretvaults/accessible

List secret vaults accessible by a given principal

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: GetAccessibleVaults

Parameters

Name In Type Required
boundaryId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

SecretVault

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults

List all secretvaults in a resource group

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: ListSecretVaults

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/config

Get list configuration for secretvaults

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: GetSecretVaultsConfig

Parameters

Name In Type Required
boundaryId path string Yes
resourceGroupName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}

Delete a secretvault

  • Authentication: required
  • IAM action: secretvault/delete — evaluated at the resource in the path
  • Operation name: DeleteSecretVault

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes
resourceName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/delete at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}

Get a specific secretvault

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: GetSecretVault

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes
resourceName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

PATCH /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}

Partially update an existing secretvault using JSON Merge Patch

  • Authentication: required
  • IAM action: secretvault/write — evaluated at the resource in the path
  • Operation name: PatchSecretVault

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes
resourceName path string Yes

Request body: any

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/write at the evaluated scope

POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}

Create a new secretvault

  • Authentication: required
  • IAM action: secretvault/write — evaluated at the resource in the path
  • Operation name: CreateSecretVault

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes
resourceName path string Yes

Request body: SecretVaultDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/write at the evaluated scope

PUT /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}

Update an existing secretvault

  • Authentication: required
  • IAM action: secretvault/write — evaluated at the resource in the path
  • Operation name: UpdateSecretVault

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroupName path string Yes
resourceName path string Yes

Request body: SecretVaultDto

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/write at the evaluated scope

GET /boundaries/{boundaryId}/resources/secretvaults

List all secretvaults across all resource groups

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: ListAllSecretVaults

Parameters

Name In Type Required
boundaryId path uuid Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

GET /boundaries/{boundaryId}/resources/secretvaults/config

Get list configuration for all secretvaults

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: GetAllSecretVaultsConfig

Parameters

Name In Type Required
boundaryId path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

Secrets

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets

List all secrets in a vault

  • Authentication: required
  • IAM action: secretvault/read — evaluated at the resource in the path
  • Operation name: ListSecrets

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
includeDeleted query boolean No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/read at the evaluated scope

DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}

Delete a secret (soft-delete if vault has it enabled)

  • Authentication: required
  • IAM action: secretvault/writeSecrets — evaluated at the resource in the path; a data action
  • Operation name: DeleteSecret

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/writeSecrets at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}

Get the current value of a secret

  • Authentication: required
  • IAM action: secretvault/readSecrets — evaluated at the resource in the path; a data action
  • Operation name: GetSecret

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/readSecrets at the evaluated scope

PUT /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}

Create or update a secret value (creates a new version)

  • Authentication: required
  • IAM action: secretvault/writeSecrets — evaluated at the resource in the path; a data action
  • Operation name: SetSecret

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Request body: SetSecretRequest

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/writeSecrets at the evaluated scope

POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/purge

Permanently purge a soft-deleted secret

  • Authentication: required
  • IAM action: secretvault/writeSecrets — evaluated at the resource in the path; a data action
  • Operation name: PurgeDeletedSecret

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/writeSecrets at the evaluated scope

POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/recover

Recover a soft-deleted secret

  • Authentication: required
  • IAM action: secretvault/writeSecrets — evaluated at the resource in the path; a data action
  • Operation name: RecoverDeletedSecret

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/writeSecrets at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/versions

List all versions of a secret

  • Authentication: required
  • IAM action: secretvault/readSecrets — evaluated at the resource in the path; a data action
  • Operation name: ListSecretVersions

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/readSecrets at the evaluated scope

GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/versions/{version}

Get a specific version of a secret

  • Authentication: required
  • IAM action: secretvault/readSecrets — evaluated at the resource in the path; a data action
  • Operation name: GetSecretVersion

Parameters

Name In Type Required
boundaryId path uuid Yes
resourceGroup path string Yes
resourceName path string Yes
secretName path string Yes
version path integer Yes

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid
403 The caller does not hold secretvault/readSecrets at the evaluated scope

Secrets (External)

GET /vaults/{vaultName}/secrets/{name}

Get a secret using the globally unique vault name (for SDK/external access)

  • Authentication: required
  • Operation name: GetSecretByVaultName

Parameters

Name In Type Required
vaultName path string Yes
name path string Yes
version query integer No

Responses

Status Meaning Body
200 OK
401 Not signed in, or the token is invalid

Other endpoints

GET /readyz

  • Authentication: none — anonymous callers are accepted
  • Operation name: StackshipReadiness

Responses

Status Meaning Body

Schemas

SecretVaultDto

Property Type Nullable
boundary string No
boundaryId uuid No
clusterId uuid No
clusterName string No
collection string No
createdAt date-time No
enablePurgeProtection boolean No
id uuid No
name string No
phase string Yes
region string No
resourceGroup string No
secretCount integer No
softDeleteEnabled boolean No
softDeleteRetentionDays integer No
status string No
tags map (string) No
vaultUri string Yes

SetSecretRequest

Property Type Nullable
contentType string Yes
enabled boolean No
expiresOn date-time Yes
notBefore date-time Yes
tags map (string) Yes
value string No