HashiCorp Vault Auth - Token API

Token auth method

OpenAPI Specification

hashicorp-vault-auth-token-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: HashiCorp Vault HTTP Auth - AppRole Auth - Token API
  description: The Vault HTTP API provides full access to Vault functionality via HTTP. Every aspect of Vault can be controlled via this API including secrets management, authentication, system configuration, identity, and policy management.
  version: 1.15.0
  contact:
    name: HashiCorp
    url: https://www.vaultproject.io/
  license:
    name: Business Source License 1.1
    url: https://github.com/hashicorp/vault/blob/main/LICENSE
servers:
- url: https://127.0.0.1:8200/v1
  description: Local Vault server
- url: https://{vault_host}:{port}/v1
  description: Custom Vault server
  variables:
    vault_host:
      default: 127.0.0.1
    port:
      default: '8200'
security:
- VaultToken: []
tags:
- name: Auth - Token
  description: Token auth method
paths:
  /auth/token/create:
    post:
      operationId: createToken
      summary: Create a token
      description: Creates a new token with specified policies and settings.
      tags:
      - Auth - Token
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: string
                policies:
                  type: array
                  items:
                    type: string
                meta:
                  type: object
                  additionalProperties:
                    type: string
                no_parent:
                  type: boolean
                no_default_policy:
                  type: boolean
                renewable:
                  type: boolean
                ttl:
                  type: string
                explicit_max_ttl:
                  type: string
                display_name:
                  type: string
                num_uses:
                  type: integer
                period:
                  type: string
                entity_alias:
                  type: string
      responses:
        '200':
          description: Token created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /auth/token/lookup:
    post:
      operationId: lookupToken
      summary: Lookup a token
      description: Returns information about the given token.
      tags:
      - Auth - Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - token
              properties:
                token:
                  type: string
      responses:
        '200':
          description: Token information
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /auth/token/lookup-self:
    get:
      operationId: lookupSelfToken
      summary: Lookup own token
      description: Returns information about the current client token.
      tags:
      - Auth - Token
      responses:
        '200':
          description: Token information
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /auth/token/renew:
    post:
      operationId: renewToken
      summary: Renew a token
      tags:
      - Auth - Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - token
              properties:
                token:
                  type: string
                increment:
                  type: string
      responses:
        '200':
          description: Token renewed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /auth/token/renew-self:
    post:
      operationId: renewSelfToken
      summary: Renew own token
      tags:
      - Auth - Token
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                increment:
                  type: string
      responses:
        '200':
          description: Token renewed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /auth/token/revoke:
    post:
      operationId: revokeToken
      summary: Revoke a token
      tags:
      - Auth - Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - token
              properties:
                token:
                  type: string
      responses:
        '204':
          description: Token revoked
  /auth/token/revoke-self:
    post:
      operationId: revokeSelfToken
      summary: Revoke own token
      tags:
      - Auth - Token
      responses:
        '204':
          description: Token revoked
components:
  schemas:
    VaultResponse:
      type: object
      properties:
        request_id:
          type: string
        lease_id:
          type: string
        renewable:
          type: boolean
        lease_duration:
          type: integer
        data:
          type: object
          additionalProperties: true
        wrap_info:
          type: object
          properties:
            token:
              type: string
            accessor:
              type: string
            ttl:
              type: integer
            creation_time:
              type: string
              format: date-time
            creation_path:
              type: string
            wrapped_accessor:
              type: string
          nullable: true
        warnings:
          type: array
          items:
            type: string
          nullable: true
        auth:
          type: object
          properties:
            client_token:
              type: string
            accessor:
              type: string
            policies:
              type: array
              items:
                type: string
            token_policies:
              type: array
              items:
                type: string
            metadata:
              type: object
              additionalProperties:
                type: string
            lease_duration:
              type: integer
            renewable:
              type: boolean
            entity_id:
              type: string
            token_type:
              type: string
            orphan:
              type: boolean
          nullable: true
  securitySchemes:
    VaultToken:
      type: apiKey
      name: X-Vault-Token
      in: header
      description: Vault client token