API reference
Every HTTP endpoint of the secrets module: authentication, IAM action, parameters, bodies and status codes.
Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.
Docs
GET /docs/secrets/manifest.json
- Authentication: required
- Operation name:
DocsManifest_secrets
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /docs/secrets/{path}
- Authentication: required
- Operation name:
DocsFile_secrets
Parameters
| Name | In | Type | Required |
|---|---|---|---|
path |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Secret Vaults
GET /boundaries/{boundaryId}/resources/secretvaults/accessible
List secret vaults accessible by a given principal
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
GetAccessibleVaults
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
SecretVault
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults
List all secretvaults in a resource group
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
ListSecretVaults
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/config
Get list configuration for secretvaults
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
GetSecretVaultsConfig
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
resourceGroupName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}
Delete a secretvault
- Authentication: required
- IAM action:
secretvault/delete— evaluated at the resource in the path - Operation name:
DeleteSecretVault
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
resourceName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/delete at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}
Get a specific secretvault
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
GetSecretVault
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
resourceName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
PATCH /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}
Partially update an existing secretvault using JSON Merge Patch
- Authentication: required
- IAM action:
secretvault/write— evaluated at the resource in the path - Operation name:
PatchSecretVault
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
resourceName |
path | string |
Yes |
Request body: any
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/write at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}
Create a new secretvault
- Authentication: required
- IAM action:
secretvault/write— evaluated at the resource in the path - Operation name:
CreateSecretVault
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
resourceName |
path | string |
Yes |
Request body: SecretVaultDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/write at the evaluated scope |
PUT /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/secretvaults/{resourceName}
Update an existing secretvault
- Authentication: required
- IAM action:
secretvault/write— evaluated at the resource in the path - Operation name:
UpdateSecretVault
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
resourceName |
path | string |
Yes |
Request body: SecretVaultDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/write at the evaluated scope |
GET /boundaries/{boundaryId}/resources/secretvaults
List all secretvaults across all resource groups
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
ListAllSecretVaults
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
GET /boundaries/{boundaryId}/resources/secretvaults/config
Get list configuration for all secretvaults
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
GetAllSecretVaultsConfig
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
Secrets
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets
List all secrets in a vault
- Authentication: required
- IAM action:
secretvault/read— evaluated at the resource in the path - Operation name:
ListSecrets
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
includeDeleted |
query | boolean |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/read at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}
Delete a secret (soft-delete if vault has it enabled)
- Authentication: required
- IAM action:
secretvault/writeSecrets— evaluated at the resource in the path; a data action - Operation name:
DeleteSecret
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/writeSecrets at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}
Get the current value of a secret
- Authentication: required
- IAM action:
secretvault/readSecrets— evaluated at the resource in the path; a data action - Operation name:
GetSecret
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/readSecrets at the evaluated scope |
PUT /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}
Create or update a secret value (creates a new version)
- Authentication: required
- IAM action:
secretvault/writeSecrets— evaluated at the resource in the path; a data action - Operation name:
SetSecret
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Request body: SetSecretRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/writeSecrets at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/purge
Permanently purge a soft-deleted secret
- Authentication: required
- IAM action:
secretvault/writeSecrets— evaluated at the resource in the path; a data action - Operation name:
PurgeDeletedSecret
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/writeSecrets at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/recover
Recover a soft-deleted secret
- Authentication: required
- IAM action:
secretvault/writeSecrets— evaluated at the resource in the path; a data action - Operation name:
RecoverDeletedSecret
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/writeSecrets at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/versions
List all versions of a secret
- Authentication: required
- IAM action:
secretvault/readSecrets— evaluated at the resource in the path; a data action - Operation name:
ListSecretVersions
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/readSecrets at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/resources/secretvaults/{resourceName}/secrets/{secretName}/versions/{version}
Get a specific version of a secret
- Authentication: required
- IAM action:
secretvault/readSecrets— evaluated at the resource in the path; a data action - Operation name:
GetSecretVersion
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
path | string |
Yes |
secretName |
path | string |
Yes |
version |
path | integer |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold secretvault/readSecrets at the evaluated scope |
Secrets (External)
GET /vaults/{vaultName}/secrets/{name}
Get a secret using the globally unique vault name (for SDK/external access)
- Authentication: required
- Operation name:
GetSecretByVaultName
Parameters
| Name | In | Type | Required |
|---|---|---|---|
vaultName |
path | string |
Yes |
name |
path | string |
Yes |
version |
query | integer |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Other endpoints
GET /readyz
- Authentication: none — anonymous callers are accepted
- Operation name:
StackshipReadiness
Responses
| Status | Meaning | Body |
|---|
Schemas
SecretVaultDto
| Property | Type | Nullable |
|---|---|---|
boundary |
string |
No |
boundaryId |
uuid |
No |
clusterId |
uuid |
No |
clusterName |
string |
No |
collection |
string |
No |
createdAt |
date-time |
No |
enablePurgeProtection |
boolean |
No |
id |
uuid |
No |
name |
string |
No |
phase |
string |
Yes |
region |
string |
No |
resourceGroup |
string |
No |
secretCount |
integer |
No |
softDeleteEnabled |
boolean |
No |
softDeleteRetentionDays |
integer |
No |
status |
string |
No |
tags |
map (string) |
No |
vaultUri |
string |
Yes |
SetSecretRequest
| Property | Type | Nullable |
|---|---|---|
contentType |
string |
Yes |
enabled |
boolean |
No |
expiresOn |
date-time |
Yes |
notBefore |
date-time |
Yes |
tags |
map (string) |
Yes |
value |
string |
No |