OpenAPI Specification
openapi: 3.0.0
info:
description: The Eon.io REST API
title: Eon accounts vaults API
version: 1.0.0
servers:
- url: /
security:
- ApiKeyAuth: []
tags:
- description: Manage backup vaults that store snapshots.
name: vaults
x-displayName: Vaults
paths:
/v1/projects/{projectId}/vaults:
post:
description: 'Description: Creates a vault in the specified project.
By default, vaults are encrypted using an Eon-managed KMS key.
However, if your requirements mandate control over encryption keys, you can use a customer-managed KMS key.
For more information, see [About Self-Managed Vault Keys].
<Error>
If you use self-managed vault keys, you assume responsibility for securing them from unauthorized access and deletion.
</Error>
[About Self-Managed Vault Keys]: /user-guide/backing-up/vaults/about-self-managed-vault-keys
'
operationId: createVault
parameters:
- description: 'ID of the project the vault is created in.
You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console.
'
example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
explode: false
in: path
name: projectId
required: true
schema:
format: uuid
type: string
style: simple
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateVaultRequest'
required: true
responses:
'201':
content:
application/json:
schema:
$ref: '#/components/schemas/CreateVaultResponse'
description: Vault created.
'409':
content:
application/json:
schema:
$ref: '#/components/schemas/createVault_409_response'
description: A vault with the same encryption key already exists in the specified region.
1XX:
description: Informational
3XX:
description: Redirect
4XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Client Error
5XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Internal Server Error
summary: Create Vault
tags:
- vaults
x-internal: false
x-data-access:
excluded: true
x-permissions:
- create:vaults
x-audit-log:
action: create
entityRefs:
- entityType: vault
in: resBody
key: vault.id
/v1/projects/{projectId}/vaults/{vaultId}:
get:
description: 'Description: Retrieves a vault.'
operationId: getVault
parameters:
- description: 'ID of the project the vault is in.
You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console.
'
example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
explode: false
in: path
name: projectId
required: true
schema:
format: uuid
type: string
style: simple
- description: ID of the vault to retrieve.
example: 36388572-9c69-5309-b362-04e7d85ae503
explode: false
in: path
name: vaultId
required: true
schema:
format: uuid
type: string
style: simple
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/GetVaultResponse'
description: Vault retrieved.
'404':
description: Project or vault wasn't found.
1XX:
description: Informational
3XX:
description: Redirect
4XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Client Error
5XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Internal Server Error
summary: Get Vault
tags:
- vaults
x-internal: false
x-data-access:
excluded: true
x-permissions:
- read:vaults
x-audit-log:
excluded: true
patch:
description: 'Description: Updates a vault''s display name.'
operationId: updateVault
parameters:
- description: 'ID of the project the vault is in.
You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console.
'
example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
explode: false
in: path
name: projectId
required: true
schema:
format: uuid
type: string
style: simple
- description: ID of the vault to update.
example: 36388572-9c69-5309-b362-04e7d85ae503
explode: false
in: path
name: vaultId
required: true
schema:
format: uuid
type: string
style: simple
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateVaultRequest'
required: true
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateVaultResponse'
description: Vault is updated.
'404':
description: Project or vault wasn't found.
1XX:
description: Informational
3XX:
description: Redirect
4XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Client Error
5XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Internal Server Error
summary: Update Vault
tags:
- vaults
x-internal: false
x-data-access:
excluded: true
x-permissions:
- update:vaults
x-audit-log:
action: update
entityRefs:
- entityType: vault
in: path
key: vaultId
/v1/projects/{projectId}/vaults/list:
post:
description: 'Description: Retrieves a list of vaults in the specified project.'
operationId: listVaults
parameters:
- description: 'ID of the project whose vaults you want to retrieve.
You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console.
'
example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
explode: false
in: path
name: projectId
required: true
schema:
format: uuid
type: string
style: simple
- allowEmptyValue: true
description: 'Cursor that points to the first record of the next page of results.
Get this value from the previous response.
To preserve the results in the same order, use the same sorting and filters in the first request as all subsequent requests.
'
example: Yjk3ODZjNjktZTIwZC00NjAxLWE1MzktZjg2NGExM2IxYTZlfDE=
explode: true
in: query
name: pageToken
required: false
schema:
format: tobedefined
type: string
style: form
- description: Maximum number of items to return in the response.
example: 10
explode: true
in: query
name: pageSize
required: false
schema:
minimum: 1
type: integer
style: form
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/ListBackupVaultResponse'
description: Vaults retrieved.
1XX:
description: Informational
3XX:
description: Redirect
4XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Client Error
5XX:
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
description: Internal Server Error
summary: List Vaults
tags:
- vaults
x-mcp: true
x-internal: false
x-data-access:
excluded: true
x-permissions:
- read:vaults
x-audit-log:
excluded: true
components:
schemas:
GetVaultResponse:
example:
vault:
providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
properties:
vault:
$ref: '#/components/schemas/BackupVault'
required:
- vault
type: object
UpdateVaultRequest:
example:
name: My new vault name
properties:
name:
description: Vault display name.
example: My new vault name
type: string
required:
- name
type: object
Provider:
description: 'Cloud provider.
`PROVIDER_UNSPECIFIED` is supported only in responses.
'
enum:
- AWS
- AZURE
- GCP
- MONGO_ATLAS
- GOOGLE_WORKSPACE
- MICROSOFT_365
- PROVIDER_UNSPECIFIED
example: AWS
type: string
x-docs-internal-enum:
- GOOGLE_WORKSPACE
- MICROSOFT_365
Error:
example:
error: error
properties:
error:
type: string
type: object
BackupVault:
example:
providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
properties:
id:
description: Vault ID.
example: 37732835-d768-5990-ba93-a7c2d2e6d754
type: string
vaultAccountId:
description: Eon-assigned ID of the vault account.
example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
type: string
providerAccountId:
description: Cloud provider-assigned ID of the vault account.
example: '123412341234'
type: string
name:
description: Vault display name.
example: AWS US East 1
type: string
region:
description: Region where the vault is located.
example: us-east-1
type: string
isManagedByEon:
description: Whether the vault is in an Eon-managed vault account.
example: true
type: boolean
vaultAttributes:
$ref: '#/components/schemas/VaultProviderAttributes'
required:
- id
- isManagedByEon
- name
- providerAccountId
- region
- vaultAccountId
- vaultAttributes
type: object
VaultProviderAttributesInput:
description: 'Cloud-provider-specific vault attributes.
'
example:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
properties:
cloudProvider:
$ref: '#/components/schemas/Provider'
aws:
$ref: '#/components/schemas/AwsVaultConfigInput'
required:
- cloudProvider
type: object
AwsVaultConfigInput:
description: 'AWS-specific vault configuration.
'
example:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
nullable: true
properties:
encryptionKey:
description: 'ARN of the KMS key used for encryption.
Omitted if the key is managed by Eon.
'
example: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
type: string
type: object
ListBackupVaultResponse:
example:
nextToken: Y2NiMGYyZmMtYjYyZi00OTc5LTgzNjQtYmQ2YjEyYzdjZTNifDE=
vaults:
- providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
- providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
totalCount: 188
properties:
vaults:
items:
$ref: '#/components/schemas/BackupVault'
type: array
nextToken:
description: 'Cursor that points to the first record of the next page of results.
Pass this value in the next request.
'
example: Y2NiMGYyZmMtYjYyZi00OTc5LTgzNjQtYmQ2YjEyYzdjZTNifDE=
type: string
totalCount:
description: Total number of restore jobs that matched the filter options.
example: 188
type: integer
required:
- totalCount
- vaults
type: object
createVault_409_response:
example:
error: error
properties:
error:
type: string
type: object
AwsVaultConfig:
description: 'AWS-specific vault configuration.
'
example:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
nullable: true
properties:
encryptionKey:
description: 'ARN of the KMS key used for encryption.
Omitted if the key is managed by Eon.
'
example: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
type: string
type: object
UpdateVaultResponse:
example:
vault:
providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
properties:
vault:
$ref: '#/components/schemas/BackupVault'
required:
- vault
type: object
VaultProviderAttributes:
description: 'Cloud-provider-specific vault attributes.
'
example:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
properties:
cloudProvider:
$ref: '#/components/schemas/Provider'
aws:
$ref: '#/components/schemas/AwsVaultConfig'
required:
- cloudProvider
type: object
CreateVaultResponse:
example:
vault:
providerAccountId: '123412341234'
name: AWS US East 1
vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
id: 37732835-d768-5990-ba93-a7c2d2e6d754
isManagedByEon: true
region: us-east-1
properties:
vault:
$ref: '#/components/schemas/BackupVault'
required:
- vault
type: object
CreateVaultRequest:
example:
name: EU central
vaultAttributes:
cloudProvider: AWS
aws:
encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62
region: eu-central-1
properties:
name:
description: Vault display name.
example: EU central
type: string
region:
description: Region where the vault is hosted.
example: eu-central-1
type: string
vaultAttributes:
$ref: '#/components/schemas/VaultProviderAttributesInput'
required:
- name
- region
- vaultAttributes
type: object
securitySchemes:
ApiKeyAuth:
bearerFormat: JWT
scheme: bearer
type: http