Aembit Credentials API

The Credentials API from Aembit — 1 operation(s) for credentials.

Operations 1

POST /edge/v1/credentials Get credentials for a Client Workload #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/aembit-credentials-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

aembit-credentials-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Aembit Edge Credentials API
  version: v1
servers:
- url: https://{tenant}.aembit.io
  variables:
    tenant:
      default: tenant
      description: Aembit Tenant ID
security:
- EdgeApiAuth: []
tags:
- name: Credentials
paths:
  /edge/v1/credentials:
    post:
      tags:
      - Credentials
      summary: Get credentials for a Client Workload
      description: Retrieves credentials for a Client Workload based on configured Access Policies
      operationId: edge-api-get-credentials
      parameters:
      - name: X-Aembit-ResourceSet
        in: header
        description: The Resource Set ID of the Access Policy to be used for this credential request. If not specified, the default Resource Set will be used.
        schema:
          type: string
          format: uuid
      requestBody:
        content:
          application/json:
            schema:
              description: Request payload for retrieving credentials for a Client Workload
              title: CredentialsRequest
              $ref: '#/components/schemas/ApiCredentialsRequest'
      responses:
        '200':
          description: Credentials returned for specified Client Workload
          content:
            application/json:
              schema:
                description: Response containing credentials that a Client Workload requests with expiration details
                $ref: '#/components/schemas/ApiCredentialsResponse'
        '400':
          description: Invalid request or missing parameters
          content:
            application/json:
              schema:
                description: DTO for a Generic API Response
                $ref: '#/components/schemas/GenericResponseDTO'
              examples:
                '400':
                  summary: 400 response example
                  value:
                    success: false
                    message: The credentials request is invalid.
                    id: 0
        '401':
          description: Unauthorized access
          content:
            application/json:
              schema:
                description: DTO for a Generic API Response
                $ref: '#/components/schemas/GenericResponseDTO'
              examples:
                '401':
                  summary: 401 response example
                  value:
                    success: false
                    message: Unauthorized access.
                    id: 0
        '403':
          description: Not applicable for this request
          content:
            application/json:
              schema:
                description: DTO for a Generic API Response
                $ref: '#/components/schemas/GenericResponseDTO'
              examples:
                '403':
                  summary: 403 response example
                  value:
                    success: false
                    message: Not applicable for this request.
                    id: 0
        '404':
          description: No client/server workload or access policy was found. Response will be of type ApiCredentialsResponse with credential type set to Unknown
          content:
            application/json:
              schema:
                description: Response containing credentials that a Client Workload requests with expiration details
                $ref: '#/components/schemas/ApiCredentialsResponse'
        '429':
          description: Too many credential requests
          content:
            application/json:
              schema:
                description: DTO for a Generic API Response
                $ref: '#/components/schemas/GenericResponseDTO'
              examples:
                '429':
                  summary: 429 response example
                  value:
                    success: false
                    message: Too many requests. Please try again later.
                    id: 0
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                description: DTO for a Generic API Response
                $ref: '#/components/schemas/GenericResponseDTO'
              examples:
                '500':
                  summary: 500 response example
                  value:
                    success: false
                    message: Failed to retrieve credentials due to an internal error.
                    id: 0
components:
  schemas:
    ProcessDTO:
      type: object
      properties:
        name:
          type:
          - 'null'
          - string
          description: Process name
        pid:
          type: integer
          description: Process identifier (PID)
          format: int32
        userId:
          type: integer
          description: User identifier running the process
          format: int32
        userName:
          type:
          - 'null'
          - string
          description: Username running the process
        exePath:
          type:
          - 'null'
          - string
          description: Executable file path of the process
        commandLine:
          type:
          - 'null'
          - string
          description: Command line running the process
        exeHash:
          type:
          - 'null'
          - string
          description: Executable hash of the process
      additionalProperties: false
      description: Process information for Client Workload identification
    StsGetCallerIdentityDTO:
      type: object
      properties:
        headers:
          type:
          - 'null'
          - object
          additionalProperties:
            type:
            - 'null'
            - string
          description: HTTP headers for AWS STS GetCallerIdentity request
        region:
          type:
          - 'null'
          - string
          description: AWS region for STS GetCallerIdentity request
      additionalProperties: false
      description: AWS STS GetCallerIdentity request data for identity verification
    GenericResponseDTO:
      type: object
      properties:
        success:
          type: boolean
          description: True if the API call was successful, False otherwise
        message:
          type:
          - 'null'
          - string
          description: Message to indicate why the API call failed
        id:
          type: integer
          description: Unique identifier of the API response
          format: int32
      additionalProperties: false
      description: DTO for a Generic API Response
    AzureAttestationDTO:
      type: object
      properties:
        attestedDocument:
          description: Azure Instance Metadata Service (IMDS) Attested Data document.
          $ref: '#/components/schemas/AzureAttestedDocumentDTO'
      additionalProperties: false
      description: Azure-specific attestation data for Client Workload identification
    K8sDTO:
      type: object
      properties:
        serviceAccountToken:
          type:
          - 'null'
          - string
          description: Kubernetes service account JWT token
      additionalProperties: false
      description: Kubernetes-specific attestation data for Kubernetes pod identification
    CrowdStrikeDTO:
      type: object
      properties:
        agentId:
          type:
          - 'null'
          - string
          description: Unique identifier for the CrowdStrike agent
      additionalProperties: false
      description: CrowdStrike agent information for endpoint security attestation
    AwsDTO:
      type: object
      properties:
        instanceIdentityDocument:
          type:
          - 'null'
          - string
          description: Base64-encoded AWS instance identity document
        instanceIdentityDocumentSignature:
          type:
          - 'null'
          - string
          description: Base64-encoded signature for AWS instance identity document verification
        lambda:
          description: AWS Lambda function information for serverless workload attestation
          $ref: '#/components/schemas/LambdaDTO'
        ecs:
          description: AWS ECS container and task metadata for workload attestation
          $ref: '#/components/schemas/AwsEcsDTO'
        stsGetCallerIdentity:
          description: AWS STS GetCallerIdentity request data for identity verification
          $ref: '#/components/schemas/StsGetCallerIdentityDTO'
      additionalProperties: false
      description: AWS-specific attestation data for Client Workload identification
    EnvironmentDTO:
      type: object
      properties:
        K8S_POD_NAME:
          type:
          - 'null'
          - string
          description: Kubernetes pod name environment variable
        CLIENT_WORKLOAD_ID:
          type:
          - 'null'
          - string
          description: Aembit Client Workload identifier environment variable
        KUBERNETES_PROVIDER_ID:
          type:
          - 'null'
          - string
          description: Kubernetes Trust Provider identifier environment variable
        AEMBIT_RESOURCE_SET_ID:
          type:
          - 'null'
          - string
          description: Aembit Resource Set identifier environment variable
      additionalProperties: false
      description: Environment variables available to the Client Workload
    NetworkInterfacesDTO:
      type: object
      properties:
        name:
          type:
          - 'null'
          - string
          description: Name of the network interface
        macAddress:
          type:
          - 'null'
          - string
          description: MAC address of the network interface
        ipv4Addresses:
          type:
          - 'null'
          - array
          items:
            type: string
          description: List of IPv4 addresses
        ipv6Addresses:
          type:
          - 'null'
          - array
          items:
            type: string
          description: List of IPv6 addresses
      additionalProperties: false
    HostDTO:
      type: object
      properties:
        hostname:
          type:
          - 'null'
          - string
          description: Client Workload hostname
        domainName:
          type:
          - 'null'
          - string
          description: Domain name of the Client Workload host
        process:
          description: Process information for Client Workload identification
          $ref: '#/components/schemas/ProcessDTO'
        sensors:
          description: Security sensor data for enhanced Client Workload attestation
          $ref: '#/components/schemas/SensorsDTO'
        systemSerialNumber:
          type:
          - 'null'
          - string
          description: Hardware serial number of the Client Workload system
        networkInterfaces:
          type:
          - 'null'
          - array
          items:
            $ref: '#/components/schemas/NetworkInterfacesDTO'
      additionalProperties: false
      description: Host system information for Client Workload attestation
    IdentityTokenAttestationDTO:
      type: object
      properties:
        identityToken:
          type:
          - 'null'
          - string
          description: Identity token for workload attestation
      additionalProperties: false
      description: JWT-based identity token attestation for CI/CD platforms
    GcpAttestationDTO:
      type: object
      properties:
        identityToken:
          type:
          - 'null'
          - string
          description: Identity token for workload attestation
        instanceDocument:
          type:
          - 'null'
          - string
          description: Base64-encoded GCP instance identity document
      additionalProperties: false
      description: GCP-specific attestation data for Client Workload identification
    AzureAttestedDocumentDTO:
      type: object
      properties:
        encoding:
          type:
          - 'null'
          - string
          description: The encoding of the IMDS document.
        signature:
          type:
          - 'null'
          - string
          description: The Base64-encoded signature (PKCS7 container) returned by the Azure IMDS 'document' field.
        nonce:
          type:
          - 'null'
          - string
          description: The cryptographic nonce passed to the IMDS endpoint.
      additionalProperties: false
      description: Azure Instance Metadata Service (IMDS) Attested Data document.
    SensorsDTO:
      type: object
      properties:
        crowdStrike:
          description: CrowdStrike agent information for endpoint security attestation
          $ref: '#/components/schemas/CrowdStrikeDTO'
      additionalProperties: false
      description: Security sensor data for enhanced Client Workload attestation
    ApiCredentialsRequest:
      title: CredentialsRequest
      required:
      - client
      - credentialType
      - server
      type: object
      properties:
        client:
          description: 'Identity and attestation details for the client workload requesting credentials.

            Populate this object with the same workload identity context used for /edge/v1/auth,

            including any platform-specific attestation fields required for that workload type (for

            example, Kubernetes service account token, OIDC identity token, or cloud instance attestation data).

            These fields are evaluated as part of access policy matching for the credentials request.'
          $ref: '#/components/schemas/ClientWorkloadDetails'
        server:
          description: Target resource details for which the credential is being requested.
          $ref: '#/components/schemas/ServerWorkloadDetails'
        credentialType:
          description: Type of credential being requested from your configured Credential Provider
          title: CredentialProviderTypes
          $ref: '#/components/schemas/CredentialProviderTypes'
        connectionMetadata:
          description: Filter values to be used if your access policy is configured with multiple credential providers
          $ref: '#/components/schemas/ConnectionMetadata'
        certSigningRequest:
          type:
          - 'null'
          - string
      additionalProperties: false
      description: Request payload for retrieving credentials for a Client Workload
    ConnectionMetadata:
      type: object
      properties:
        accountName:
          type:
          - 'null'
          - string
          description: The Snowflake username to filter on
        accessKeyId:
          type:
          - 'null'
          - string
          description: The AWS access key ID to filter on
        headerName:
          type:
          - 'null'
          - string
          description: The Header Name to filter on
        headerValue:
          type:
          - 'null'
          - string
          description: The Header Value to filter on
        httpBodyFieldPath:
          type:
          - 'null'
          - string
          description: The HTTP Body Field Path to filter on
        httpBodyFieldValue:
          type:
          - 'null'
          - string
          description: The HTTP Body Field Value to filter on
      additionalProperties: false
      description: Filter for multi-credential provider access policy credential request
    ServerWorkloadDetails:
      type: object
      properties:
        transportProtocol:
          description: The protocol used to connect to the target resource. Default is TCP.
          $ref: '#/components/schemas/TransportProtocol'
        host:
          type:
          - 'null'
          - string
          description: The hostname, IP address, or FQDN of the target resource
        port:
          type: integer
          description: The port number of the target resource.
          format: int32
      additionalProperties: false
      description: Target resource details for which the credential is being requested. These fields are used to match the request against your configured Access Policies.
    ApiCredentialsResponse:
      title: CredentialsResponse
      type: object
      properties:
        credentialType:
          description: Type of credential returned by your configured Credential Provider
          $ref: '#/components/schemas/CredentialProviderTypes'
        expiresAt:
          type:
          - 'null'
          - string
          description: Token expiration time in ISO 8601 format, null for non-expiring credentials
          format: date-time
        data:
          description: Credential data returned by your configured Credential Provider
          $ref: '#/components/schemas/EdgeCredentials'
      additionalProperties: false
      description: Response containing credentials that a Client Workload requests with expiration details
    ClientWorkloadDetails:
      type: object
      properties:
        sourceIP:
          type:
          - 'null'
          - string
          description: IP address of the requesting Client Workload
        aws:
          description: AWS-specific attestation data for Client Workload identification
          $ref: '#/components/schemas/AwsDTO'
        azure:
          description: Azure-specific attestation data for Client Workload identification
          $ref: '#/components/schemas/AzureAttestationDTO'
        gcp:
          description: GCP-specific attestation data for Client Workload identification
          $ref: '#/components/schemas/GcpAttestationDTO'
        os:
          description: Operating system environment information for Client Workload attestation
          $ref: '#/components/schemas/OsDTO'
        k8s:
          description: Kubernetes-specific attestation data for Kubernetes pod identification
          $ref: '#/components/schemas/K8sDTO'
        host:
          description: Host system information for Client Workload attestation
          $ref: '#/components/schemas/HostDTO'
        github:
          description: JWT-based identity token attestation for CI/CD platforms
          $ref: '#/components/schemas/IdentityTokenAttestationDTO'
        terraform:
          description: JWT-based identity token attestation for CI/CD platforms
          $ref: '#/components/schemas/IdentityTokenAttestationDTO'
        gitlab:
          description: JWT-based identity token attestation for CI/CD platforms
          $ref: '#/components/schemas/IdentityTokenAttestationDTO'
        oidc:
          description: JWT-based identity token attestation for CI/CD platforms
          $ref: '#/components/schemas/IdentityTokenAttestationDTO'
      additionalProperties: false
      description: Identity and attestation information for a Client Workload requesting credentials
    TransportProtocol:
      enum:
      - TCP
      type: string
    CredentialProviderTypes:
      title: CredentialProviderTypes
      enum:
      - Unknown
      - ApiKey
      - UsernamePassword
      - GoogleWorkloadIdentityFederation
      - OAuthToken
      - AwsStsFederation
      - X509Svid
      type: string
      description: 'Type of credential being requested from your configured Credential Provider.

        Note: Use ''OAuthToken'' for Azure Entra ID, Microsoft, and generic OAuth2 providers.'
    OsDTO:
      type: object
      properties:
        environment:
          description: Environment variables available to the Client Workload
          $ref: '#/components/schemas/EnvironmentDTO'
      additionalProperties: false
      description: Operating system environment information for Client Workload attestation
    AwsEcsDTO:
      type: object
      properties:
        containerMetadata:
          type:
          - 'null'
          - string
          description: JSON string containing AWS ECS container metadata
        taskMetadata:
          type:
          - 'null'
          - string
          description: JSON string containing AWS ECS task metadata
      additionalProperties: false
      description: AWS ECS container and task metadata for workload attestation
    LambdaDTO:
      type: object
      properties:
        arn:
          type:
          - 'null'
          - string
          description: AWS Lambda function ARN
      additionalProperties: false
      description: AWS Lambda function information for serverless workload attestation
    EdgeCredentials:
      type: object
      properties:
        apiKey:
          type:
          - 'null'
          - string
          description: API key credential for authenticating to target services
        token:
          type:
          - 'null'
          - string
          description: "Bearer token credential for authenticating to target services/\nThis field contains the result for: \nGoogleWorkloadIdentityFederation (GCP WIF Token), GitLab, GitHub,\nand generic JWT/OIDC credentials."
        username:
          type:
          - 'null'
          - string
          description: Username for basic authentication credentials
        password:
          type:
          - 'null'
          - string
          description: Password for basic authentication credentials
        awsAccessKeyId:
          type:
          - 'null'
          - string
          description: AWS access key ID for programmatic access
        awsSecretAccessKey:
          type:
          - 'null'
          - string
          description: AWS secret access key for programmatic access
        awsSessionToken:
          type:
          - 'null'
          - string
          description: AWS session token for temporary credentials
      additionalProperties: false
      description: "    Credential data returned to Client Workloads based on your configured Credential Providers\n    For AWS (AwsStsFederation), look in the aws* fields.\n    For API Key and Username/Password, look in their respective fields.\n    For all other types (GCP, OAuth, OIDC, Aembit), the result is in the 'token' field."
  securitySchemes:
    EdgeApiAuth:
      type: http
      description: Use Aembit Edge API access token obtained via the /edge/v1/auth endpoint
      scheme: bearer
      bearerFormat: JWT