HashiCorp Vault Identity API

Identity secrets engine

OpenAPI Specification

hashicorp-vault-identity-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: HashiCorp Vault HTTP Auth - AppRole Identity API
  description: The Vault HTTP API provides full access to Vault functionality via HTTP. Every aspect of Vault can be controlled via this API including secrets management, authentication, system configuration, identity, and policy management.
  version: 1.15.0
  contact:
    name: HashiCorp
    url: https://www.vaultproject.io/
  license:
    name: Business Source License 1.1
    url: https://github.com/hashicorp/vault/blob/main/LICENSE
servers:
- url: https://127.0.0.1:8200/v1
  description: Local Vault server
- url: https://{vault_host}:{port}/v1
  description: Custom Vault server
  variables:
    vault_host:
      default: 127.0.0.1
    port:
      default: '8200'
security:
- VaultToken: []
tags:
- name: Identity
  description: Identity secrets engine
paths:
  /identity/entity:
    post:
      operationId: createEntity
      summary: Create an identity entity
      tags:
      - Identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                metadata:
                  type: object
                  additionalProperties:
                    type: string
                policies:
                  type: array
                  items:
                    type: string
                disabled:
                  type: boolean
      responses:
        '200':
          description: Entity created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
  /identity/entity/id/{id}:
    get:
      operationId: getEntity
      summary: Read an entity by ID
      tags:
      - Identity
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Entity details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultResponse'
    post:
      operationId: updateEntity
      summary: Update an entity
      tags:
      - Identity
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                metadata:
                  type: object
                  additionalProperties:
                    type: string
                policies:
                  type: array
                  items:
                    type: string
                disabled:
                  type: boolean
      responses:
        '200':
          description: Entity updated
    delete:
      operationId: deleteEntity
      summary: Delete an entity
      tags:
      - Identity
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Entity deleted
components:
  schemas:
    VaultResponse:
      type: object
      properties:
        request_id:
          type: string
        lease_id:
          type: string
        renewable:
          type: boolean
        lease_duration:
          type: integer
        data:
          type: object
          additionalProperties: true
        wrap_info:
          type: object
          properties:
            token:
              type: string
            accessor:
              type: string
            ttl:
              type: integer
            creation_time:
              type: string
              format: date-time
            creation_path:
              type: string
            wrapped_accessor:
              type: string
          nullable: true
        warnings:
          type: array
          items:
            type: string
          nullable: true
        auth:
          type: object
          properties:
            client_token:
              type: string
            accessor:
              type: string
            policies:
              type: array
              items:
                type: string
            token_policies:
              type: array
              items:
                type: string
            metadata:
              type: object
              additionalProperties:
                type: string
            lease_duration:
              type: integer
            renewable:
              type: boolean
            entity_id:
              type: string
            token_type:
              type: string
            orphan:
              type: boolean
          nullable: true
  securitySchemes:
    VaultToken:
      type: apiKey
      name: X-Vault-Token
      in: header
      description: Vault client token