CyberArk Secrets API

Store and retrieve secret values bound to variable resources.

OpenAPI Specification

cyberark-secrets-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: CyberArk Conjur Manager Authentication Secrets API
  description: Conjur Secrets Manager is CyberArk's machine-identity and secrets management platform, available as Conjur Open Source, Conjur Enterprise (Self-Hosted), and Conjur Cloud (SaaS). The REST API enables authenticating hosts and users, loading and updating policies, storing and retrieving secrets, rotating credentials, managing public keys, and querying audit information. The canonical OpenAPI specification is published at github.com/cyberark/conjur-openapi-spec; this file is a curated profile of the most-used endpoints aligned with CyberArk Secrets Manager Self-Hosted and SaaS.
  version: '1.0'
  contact:
    name: CyberArk Developer
    url: https://developer.cyberark.com
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: https://conjur.example.com
  description: Conjur Self-Hosted appliance (replace with appliance hostname)
- url: https://{tenant}.secretsmgr.cyberark.cloud/api
  description: Conjur Cloud tenant
  variables:
    tenant:
      default: tenant
      description: CyberArk Conjur Cloud tenant subdomain
security:
- ConjurAuth: []
tags:
- name: Secrets
  description: Store and retrieve secret values bound to variable resources.
paths:
  /secrets/{account}/{kind}/{identifier}:
    get:
      tags:
      - Secrets
      summary: Retrieve secret value
      operationId: retrieveSecret
      parameters:
      - name: account
        in: path
        required: true
        schema:
          type: string
      - name: kind
        in: path
        required: true
        schema:
          type: string
          enum:
          - variable
      - name: identifier
        in: path
        required: true
        schema:
          type: string
      - name: version
        in: query
        required: false
        schema:
          type: integer
      responses:
        '200':
          description: Secret value
          content:
            text/plain:
              schema:
                type: string
        '401':
          description: Unauthorized
        '404':
          description: Not found
    post:
      tags:
      - Secrets
      summary: Store secret value
      operationId: addSecret
      parameters:
      - name: account
        in: path
        required: true
        schema:
          type: string
      - name: kind
        in: path
        required: true
        schema:
          type: string
          enum:
          - variable
      - name: identifier
        in: path
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          text/plain:
            schema:
              type: string
      responses:
        '201':
          description: Secret stored
components:
  securitySchemes:
    ConjurAuth:
      type: http
      scheme: bearer
      bearerFormat: ConjurAccessToken
externalDocs:
  description: Conjur OpenAPI Specification (canonical)
  url: https://github.com/cyberark/conjur-openapi-spec