OpenAPI Specification
openapi: 3.1.0
info:
title: HashiCorp Vault HTTP Auth - AppRole Auth - Token API
description: The Vault HTTP API provides full access to Vault functionality via HTTP. Every aspect of Vault can be controlled via this API including secrets management, authentication, system configuration, identity, and policy management.
version: 1.15.0
contact:
name: HashiCorp
url: https://www.vaultproject.io/
license:
name: Business Source License 1.1
url: https://github.com/hashicorp/vault/blob/main/LICENSE
servers:
- url: https://127.0.0.1:8200/v1
description: Local Vault server
- url: https://{vault_host}:{port}/v1
description: Custom Vault server
variables:
vault_host:
default: 127.0.0.1
port:
default: '8200'
security:
- VaultToken: []
tags:
- name: Auth - Token
description: Token auth method
paths:
/auth/token/create:
post:
operationId: createToken
summary: Create a token
description: Creates a new token with specified policies and settings.
tags:
- Auth - Token
requestBody:
content:
application/json:
schema:
type: object
properties:
id:
type: string
policies:
type: array
items:
type: string
meta:
type: object
additionalProperties:
type: string
no_parent:
type: boolean
no_default_policy:
type: boolean
renewable:
type: boolean
ttl:
type: string
explicit_max_ttl:
type: string
display_name:
type: string
num_uses:
type: integer
period:
type: string
entity_alias:
type: string
responses:
'200':
description: Token created
content:
application/json:
schema:
$ref: '#/components/schemas/VaultResponse'
/auth/token/lookup:
post:
operationId: lookupToken
summary: Lookup a token
description: Returns information about the given token.
tags:
- Auth - Token
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- token
properties:
token:
type: string
responses:
'200':
description: Token information
content:
application/json:
schema:
$ref: '#/components/schemas/VaultResponse'
/auth/token/lookup-self:
get:
operationId: lookupSelfToken
summary: Lookup own token
description: Returns information about the current client token.
tags:
- Auth - Token
responses:
'200':
description: Token information
content:
application/json:
schema:
$ref: '#/components/schemas/VaultResponse'
/auth/token/renew:
post:
operationId: renewToken
summary: Renew a token
tags:
- Auth - Token
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- token
properties:
token:
type: string
increment:
type: string
responses:
'200':
description: Token renewed
content:
application/json:
schema:
$ref: '#/components/schemas/VaultResponse'
/auth/token/renew-self:
post:
operationId: renewSelfToken
summary: Renew own token
tags:
- Auth - Token
requestBody:
content:
application/json:
schema:
type: object
properties:
increment:
type: string
responses:
'200':
description: Token renewed
content:
application/json:
schema:
$ref: '#/components/schemas/VaultResponse'
/auth/token/revoke:
post:
operationId: revokeToken
summary: Revoke a token
tags:
- Auth - Token
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- token
properties:
token:
type: string
responses:
'204':
description: Token revoked
/auth/token/revoke-self:
post:
operationId: revokeSelfToken
summary: Revoke own token
tags:
- Auth - Token
responses:
'204':
description: Token revoked
components:
schemas:
VaultResponse:
type: object
properties:
request_id:
type: string
lease_id:
type: string
renewable:
type: boolean
lease_duration:
type: integer
data:
type: object
additionalProperties: true
wrap_info:
type: object
properties:
token:
type: string
accessor:
type: string
ttl:
type: integer
creation_time:
type: string
format: date-time
creation_path:
type: string
wrapped_accessor:
type: string
nullable: true
warnings:
type: array
items:
type: string
nullable: true
auth:
type: object
properties:
client_token:
type: string
accessor:
type: string
policies:
type: array
items:
type: string
token_policies:
type: array
items:
type: string
metadata:
type: object
additionalProperties:
type: string
lease_duration:
type: integer
renewable:
type: boolean
entity_id:
type: string
token_type:
type: string
orphan:
type: boolean
nullable: true
securitySchemes:
VaultToken:
type: apiKey
name: X-Vault-Token
in: header
description: Vault client token