HashiCorp System API

The System API from HashiCorp — 107 operation(s) for system.

Operations 149

GET /sys/audit HashiCorp List the enabled audit devices #
POST /sys/audit-hash/{path} HashiCorp The hash of the given string via the given audit backend #
POST /sys/audit/{path} HashiCorp Enable a new audit device at the supplied path #
DELETE /sys/audit/{path} HashiCorp Disable the audit device at the given path #
GET /sys/auth HashiCorp List the currently enabled credential backends #
POST /sys/auth/{path} HashiCorp Enables a new auth method #
DELETE /sys/auth/{path} HashiCorp Disable the auth method at the given auth path #
GET /sys/auth/{path}/tune HashiCorp Reads the given auth path's configuration #
POST /sys/auth/{path}/tune HashiCorp Tune configuration parameters for a given auth path #
POST /sys/capabilities HashiCorp Fetches the capabilities of the given token on the given path #
POST /sys/capabilities-accessor HashiCorp Fetches the capabilities of the token associated with the given… #
POST /sys/capabilities-self HashiCorp Fetches the capabilities of the given token on the given path #
GET /sys/config/auditing/request-headers HashiCorp List the request headers that are configured to be audited #
GET /sys/config/auditing/request-headers/{header} HashiCorp List the information for the given request header #
POST /sys/config/auditing/request-headers/{header} HashiCorp Enable auditing of a header #
DELETE /sys/config/auditing/request-headers/{header} HashiCorp Disable auditing of the given request header #
GET /sys/config/cors HashiCorp Return the current CORS settings #
POST /sys/config/cors HashiCorp Configure the CORS settings #
DELETE /sys/config/cors HashiCorp Remove any CORS settings #
POST /sys/config/reload/{subsystem} HashiCorp Reload the given subsystem #
GET /sys/config/state/sanitized HashiCorp Return a sanitized version of the Vault server configuration #
GET /sys/config/ui/headers/ HashiCorp Return a list of configured UI headers #
GET /sys/config/ui/headers/{header} HashiCorp Return the given UI header's configuration #
POST /sys/config/ui/headers/{header} HashiCorp Configure the values to be returned for the UI header #
DELETE /sys/config/ui/headers/{header} HashiCorp Remove a UI header #
GET /sys/generate-root HashiCorp Read the configuration and progress of the current root generation… #
POST /sys/generate-root HashiCorp Initializes a new root generation attempt #
DELETE /sys/generate-root HashiCorp Cancels any in-progress root generation attempt #
GET /sys/generate-root/attempt HashiCorp Read the configuration and progress of the current root generation… #
POST /sys/generate-root/attempt HashiCorp Initializes a new root generation attempt #
DELETE /sys/generate-root/attempt HashiCorp Cancels any in-progress root generation attempt #
POST /sys/generate-root/update HashiCorp Enter a single master key share to progress the root generation… #
GET /sys/health HashiCorp Returns the health status of Vault #
GET /sys/host-info HashiCorp Information about the host instance that this Vault server is running… #
GET /sys/init HashiCorp Returns the initialization status of Vault #
POST /sys/init HashiCorp Initialize a new Vault #
GET /sys/internal/counters/activity HashiCorp Report the client count metrics, for this namespace and all child… #
GET /sys/internal/counters/activity/monthly HashiCorp Report the number of clients for this month, for this namespace and… #
GET /sys/internal/counters/config HashiCorp Read the client count tracking configuration #
POST /sys/internal/counters/config HashiCorp Enable or disable collection of client count, set retention period… #
GET /sys/internal/counters/entities HashiCorp Backwards compatibility is not guaranteed for this API #
GET /sys/internal/counters/requests HashiCorp Backwards compatibility is not guaranteed for this API #
GET /sys/internal/counters/tokens HashiCorp Backwards compatibility is not guaranteed for this API #
GET /sys/internal/specs/openapi HashiCorp Generate an OpenAPI 3 document of all mounted paths #
GET /sys/internal/ui/feature-flags HashiCorp Lists enabled feature flags #
GET /sys/internal/ui/mounts HashiCorp Lists all enabled and visible auth and secrets mounts #
GET /sys/internal/ui/mounts/{path} HashiCorp Return information about the given mount #
GET /sys/internal/ui/namespaces HashiCorp Backwards compatibility is not guaranteed for this API #
GET /sys/internal/ui/resultant-acl HashiCorp Backwards compatibility is not guaranteed for this API #
GET /sys/key-status HashiCorp Provides information about the backend encryption key #
GET /sys/leader HashiCorp Returns the high availability status and current leader instance of… #
GET /sys/leases HashiCorp List leases associated with this Vault cluster #
GET /sys/leases/count HashiCorp Count of leases associated with this Vault cluster #
POST /sys/leases/lookup HashiCorp Retrieve lease metadata #
GET /sys/leases/lookup/ HashiCorp Returns a list of lease ids #
GET /sys/leases/lookup/{prefix} HashiCorp Returns a list of lease ids #
POST /sys/leases/renew HashiCorp Renews a lease, requesting to extend the lease #
POST /sys/leases/renew/{url_lease_id} HashiCorp Renews a lease, requesting to extend the lease #
POST /sys/leases/revoke HashiCorp Revokes a lease immediately #
POST /sys/leases/revoke-force/{prefix} HashiCorp Revokes all secrets or tokens generated under a given prefix… #
POST /sys/leases/revoke-prefix/{prefix} HashiCorp Revokes all secrets (via a lease ID prefix) or tokens (via the… #
POST /sys/leases/revoke/{url_lease_id} HashiCorp Revokes a lease immediately #
POST /sys/leases/tidy HashiCorp This endpoint performs cleanup tasks that can be run if certain error… #
GET /sys/metrics HashiCorp Export the metrics aggregated for telemetry purpose #
GET /sys/monitor Get sys monitor #
GET /sys/mounts HashiCorp List the currently mounted backends #
POST /sys/mounts/{path} HashiCorp Enable a new secrets engine at the given path #
DELETE /sys/mounts/{path} HashiCorp Disable the mount point specified at the given path #
GET /sys/mounts/{path}/tune HashiCorp Tune backend configuration parameters for this mount #
POST /sys/mounts/{path}/tune HashiCorp Tune backend configuration parameters for this mount #
GET /sys/plugins/catalog HashiCorp Lists all the plugins known to Vault #
GET /sys/plugins/catalog/{name} HashiCorp Return the configuration data for the plugin with the given name #
POST /sys/plugins/catalog/{name} HashiCorp Register a new plugin, or updates an existing one with the supplied… #
DELETE /sys/plugins/catalog/{name} HashiCorp Remove the plugin with the given name #
GET /sys/plugins/catalog/{type} HashiCorp List the plugins in the catalog #
GET /sys/plugins/catalog/{type}/{name} HashiCorp Return the configuration data for the plugin with the given name #
POST /sys/plugins/catalog/{type}/{name} HashiCorp Register a new plugin, or updates an existing one with the supplied… #
DELETE /sys/plugins/catalog/{type}/{name} HashiCorp Remove the plugin with the given name #
POST /sys/plugins/reload/backend HashiCorp Reload mounted plugin backends #
GET /sys/policies/acl HashiCorp List the configured access control policies #
GET /sys/policies/acl/{name} HashiCorp Retrieve information about the named ACL policy #
POST /sys/policies/acl/{name} HashiCorp Add a new or update an existing ACL policy #
DELETE /sys/policies/acl/{name} HashiCorp Delete the ACL policy with the given name #
GET /sys/policies/password/{name} HashiCorp Retrieve an existing password policy #
POST /sys/policies/password/{name} HashiCorp Add a new or update an existing password policy #
DELETE /sys/policies/password/{name} HashiCorp Delete a password policy #
GET /sys/policies/password/{name}/generate HashiCorp Generate a password from an existing password policy #
GET /sys/policy HashiCorp List the configured access control policies #
GET /sys/policy/{name} HashiCorp Retrieve the policy body for the named policy #
POST /sys/policy/{name} HashiCorp Add a new or update an existing policy #
DELETE /sys/policy/{name} HashiCorp Delete the policy with the given name #
GET /sys/pprof/ HashiCorp Returns an HTML page listing the available profiles #
GET /sys/pprof/allocs HashiCorp Returns a sampling of all past memory allocations #
GET /sys/pprof/block HashiCorp Returns stack traces that led to blocking on synchronization… #
GET /sys/pprof/cmdline HashiCorp Returns the running program's command line #
GET /sys/pprof/goroutine HashiCorp Returns stack traces of all current goroutines #
GET /sys/pprof/heap HashiCorp Returns a sampling of memory allocations of live object #
GET /sys/pprof/mutex HashiCorp Returns stack traces of holders of contended mutexes #
GET /sys/pprof/profile HashiCorp Returns a pprof-formatted cpu profile payload #
GET /sys/pprof/symbol HashiCorp Returns the program counters listed in the request #
GET /sys/pprof/threadcreate HashiCorp Returns stack traces that led to the creation of new OS threads #
GET /sys/pprof/trace HashiCorp Returns the execution trace in binary form #
GET /sys/quotas/config Get sys quotas config #
POST /sys/quotas/config Post sys quotas config #
GET /sys/quotas/rate-limit Get sys quotas rate limit #
GET /sys/quotas/rate-limit/{name} Get sys quotas rate limit name #
POST /sys/quotas/rate-limit/{name} Post sys quotas rate limit name #
DELETE /sys/quotas/rate-limit/{name} Delete sys quotas rate limit name #
GET /sys/raw HashiCorp Read the value of the key at the given path #
POST /sys/raw HashiCorp Update the value of the key at the given path #
DELETE /sys/raw HashiCorp Delete the key with given path #
GET /sys/raw/{path} HashiCorp Read the value of the key at the given path #
POST /sys/raw/{path} HashiCorp Update the value of the key at the given path #
DELETE /sys/raw/{path} HashiCorp Delete the key with given path #
GET /sys/rekey/backup HashiCorp Return the backup copy of PGP-encrypted unseal keys #
DELETE /sys/rekey/backup HashiCorp Delete the backup copy of PGP-encrypted unseal keys #
GET /sys/rekey/init HashiCorp Reads the configuration and progress of the current rekey attempt #
POST /sys/rekey/init HashiCorp Initializes a new rekey attempt #
DELETE /sys/rekey/init HashiCorp Cancels any in-progress rekey #
GET /sys/rekey/recovery-key-backup HashiCorp Allows fetching or deleting the backup of the rotated unseal keys #
DELETE /sys/rekey/recovery-key-backup HashiCorp Allows fetching or deleting the backup of the rotated unseal keys #
POST /sys/rekey/update HashiCorp Enter a single master key share to progress the rekey of the Vault #
GET /sys/rekey/verify HashiCorp Read the configuration and progress of the current rekey verification… #
POST /sys/rekey/verify HashiCorp Enter a single new key share to progress the rekey verification… #
DELETE /sys/rekey/verify HashiCorp Cancel any in-progress rekey verification operation #
POST /sys/remount HashiCorp Move the mount point of an already-mounted backend #
POST /sys/renew HashiCorp Renews a lease, requesting to extend the lease #
POST /sys/renew/{url_lease_id} HashiCorp Renews a lease, requesting to extend the lease #
GET /sys/replication/status Get sys replication status #
POST /sys/revoke HashiCorp Revokes a lease immediately #
POST /sys/revoke-force/{prefix} HashiCorp Revokes all secrets or tokens generated under a given prefix… #
POST /sys/revoke-prefix/{prefix} HashiCorp Revokes all secrets (via a lease ID prefix) or tokens (via the… #
POST /sys/revoke/{url_lease_id} HashiCorp Revokes a lease immediately #
POST /sys/rotate HashiCorp Rotates the backend encryption key used to persist data #
GET /sys/rotate/config Get sys rotate config #
POST /sys/rotate/config Post sys rotate config #
POST /sys/seal HashiCorp Seal the Vault #
GET /sys/seal-status HashiCorp Check the seal status of a Vault #
POST /sys/step-down HashiCorp Cause the node to give up active status #
POST /sys/tools/hash HashiCorp Generate a hash sum for input data #
POST /sys/tools/hash/{urlalgorithm} HashiCorp Generate a hash sum for input data #
POST /sys/tools/random HashiCorp Generate random bytes #
POST /sys/tools/random/{urlbytes} HashiCorp Generate random bytes #
POST /sys/unseal HashiCorp Unseal the Vault #
GET /sys/wrapping/lookup HashiCorp Look up wrapping properties for the requester's token #
POST /sys/wrapping/lookup HashiCorp Look up wrapping properties for the given token #
POST /sys/wrapping/rewrap HashiCorp Rotates a response-wrapped token #
POST /sys/wrapping/unwrap HashiCorp Unwraps a response-wrapped token #
POST /sys/wrapping/wrap HashiCorp Response-wraps an arbitrary JSON object #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/hashicorp-system-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

hashicorp-system-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: HashiCorp Vault System API
  description: HTTP API that gives you full access to Vault. All API routes are prefixed with `/v1/`.
  version: 1.9.3
  license:
    name: Mozilla Public License 2.0
    url: https://www.mozilla.org/en-US/MPL/2.0
tags:


# --- truncated at 32 KB (85 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/hashicorp/refs/heads/main/openapi/hashicorp-system-api-openapi.yml