Infisical Secret Sharing API
The Secret Sharing API from Infisical — 3 operation(s) for secret sharing.
The Secret Sharing API from Infisical — 3 operation(s) for secret sharing.
openapi: 3.0.3
info:
title: Infisical Admin Secret Sharing API
description: List of all available APIs that can be consumed
version: 0.0.1
servers:
- url: https://us.infisical.com
description: Production server (US)
- url: https://eu.infisical.com
description: Production server (EU)
- url: http://localhost:8080
description: Local server
tags:
- name: Secret Sharing
paths:
/api/v1/shared-secrets:
get:
operationId: listSharedSecrets
tags:
- Secret Sharing
description: List all shared secrets created by the authenticated user or identity in their current organization.
parameters:
- schema:
type: number
minimum: 0
maximum: 100
default: 0
in: query
name: offset
required: false
description: The offset to start listing shared secrets from. Used for pagination.
- schema:
type: number
minimum: 1
maximum: 100
default: 25
in: query
name: limit
required: false
description: The maximum number of shared secrets to return. Max is 100.
responses:
'200':
description: Default Response
content:
application/json:
schema:
type: object
properties:
secrets:
type: array
items:
type: object
properties:
id:
type: string
expiresAt:
type: string
format: date-time
userId:
type: string
format: uuid
nullable: true
orgId:
type: string
format: uuid
nullable: true
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
expiresAfterViews:
type: number
nullable: true
accessType:
type: string
default: anyone
name:
type: string
nullable: true
lastViewedAt:
type: string
format: date-time
nullable: true
type:
type: string
default: share
authorizedEmails:
nullable: true
identityId:
type: string
format: uuid
nullable: true
allowExternalEmails:
type: boolean
default: false
nullable: true
required:
- id
- expiresAt
- createdAt
- updatedAt
additionalProperties: false
totalCount:
type: number
required:
- secrets
- totalCount
additionalProperties: false
'400':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 400
message:
type: string
error:
type: string
details: {}
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'401':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 401
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'403':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 403
message:
type: string
details: {}
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'404':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 404
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'422':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 422
message: {}
error:
type: string
required:
- reqId
- statusCode
- error
additionalProperties: false
'500':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 500
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
post:
operationId: createSharedSecret
tags:
- Secret Sharing
description: Create a new shared secret that can be accessed by a link.
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
maxLength: 50
description: An optional name for the shared secret for easier identification.
password:
type: string
description: An optional password to protect the shared secret. Recipients will need to provide this password to access the secret.
secretValue:
type: string
maxLength: 10000
description: The secret value to share.
expiresIn:
type: string
default: 30d
description: The duration after which the shared secret will expire. Accepts formats like '30d', '24h', '1w'. Maximum is 30 days, minimum is 5 minutes.
maxViews:
type: number
minimum: 1
description: The maximum number of times the shared secret can be viewed before it expires. If not provided, unlimited views are allowed.
accessType:
type: string
enum:
- anyone
- organization
default: organization
description: Determines who can access the shared secret. 'organization' restricts access to users within your organization. 'anyone' allows access to anyone with the link. Defaults to 'organization'.
authorizedEmails:
type: array
items:
type: string
format: email
maxItems: 100
description: An optional array of email addresses to share the secret with. Maximum 100 emails. Organization members in the list get direct access. When allowExternalEmails is enabled, non-member emails are also accepted and recipients will receive the secret link via email, but must use the password to access it.
allowExternalEmails:
type: boolean
description: When true, allows sharing with email addresses that do not belong to Infisical. A password is required when this option is enabled. External recipients will receive the secret link via email and must enter the password to access it.
required:
- secretValue
additionalProperties: false
responses:
'200':
description: Default Response
content:
application/json:
schema:
type: object
properties:
id:
type: string
expiresAt:
type: string
format: date-time
userId:
type: string
format: uuid
nullable: true
orgId:
type: string
format: uuid
nullable: true
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
expiresAfterViews:
type: number
nullable: true
accessType:
type: string
default: anyone
name:
type: string
nullable: true
lastViewedAt:
type: string
format: date-time
nullable: true
type:
type: string
default: share
authorizedEmails:
nullable: true
identityId:
type: string
format: uuid
nullable: true
allowExternalEmails:
type: boolean
default: false
nullable: true
sharedSecretLink:
type: string
required:
- id
- expiresAt
- createdAt
- updatedAt
- sharedSecretLink
additionalProperties: false
'400':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 400
message:
type: string
error:
type: string
details: {}
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'401':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 401
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'403':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 403
message:
type: string
details: {}
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'404':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 404
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'422':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 422
message: {}
error:
type: string
required:
- reqId
- statusCode
- error
additionalProperties: false
'500':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 500
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
/api/v1/shared-secrets/{id}:
get:
operationId: getSharedSecretById
tags:
- Secret Sharing
description: Returns the full shared secret object without revealing the secret value. Authentication is required for shared secrets that are scoped to an organization.
parameters:
- schema:
type: string
in: path
name: id
required: true
description: The ID of the shared secret to retrieve.
responses:
'200':
description: Default Response
content:
application/json:
schema:
type: object
properties:
id:
type: string
expiresAt:
type: string
format: date-time
userId:
type: string
format: uuid
nullable: true
orgId:
type: string
format: uuid
nullable: true
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
expiresAfterViews:
type: number
nullable: true
accessType:
type: string
default: anyone
name:
type: string
nullable: true
lastViewedAt:
type: string
format: date-time
nullable: true
type:
type: string
default: share
identityId:
type: string
format: uuid
nullable: true
isPasswordProtected:
type: boolean
description: Whether the shared secret is protected by a password.
isAuthorizedUser:
type: boolean
description: Whether the current user is an authorized org member. If false, the user must provide a password.
required:
- id
- expiresAt
- createdAt
- updatedAt
- isPasswordProtected
- isAuthorizedUser
additionalProperties: false
'400':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 400
message:
type: string
error:
type: string
details: {}
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'401':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 401
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'403':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 403
message:
type: string
details: {}
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'404':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 404
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'422':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 422
message: {}
error:
type: string
required:
- reqId
- statusCode
- error
additionalProperties: false
'500':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 500
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
delete:
operationId: deleteSharedSecret
tags:
- Secret Sharing
description: Delete a shared secret by its ID.
parameters:
- schema:
type: string
in: path
name: id
required: true
description: The ID of the shared secret to delete.
responses:
'200':
description: Default Response
content:
application/json:
schema:
type: object
properties:
id:
type: string
expiresAt:
type: string
format: date-time
userId:
type: string
format: uuid
nullable: true
orgId:
type: string
format: uuid
nullable: true
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
expiresAfterViews:
type: number
nullable: true
accessType:
type: string
default: anyone
name:
type: string
nullable: true
lastViewedAt:
type: string
format: date-time
nullable: true
type:
type: string
default: share
authorizedEmails:
nullable: true
identityId:
type: string
format: uuid
nullable: true
allowExternalEmails:
type: boolean
default: false
nullable: true
required:
- id
- expiresAt
- createdAt
- updatedAt
additionalProperties: false
'400':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 400
message:
type: string
error:
type: string
details: {}
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'401':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 401
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'403':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 403
message:
type: string
details: {}
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'404':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 404
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'422':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 422
message: {}
error:
type: string
required:
- reqId
- statusCode
- error
additionalProperties: false
'500':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 500
message:
type: string
error:
type: string
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
/api/v1/shared-secrets/{id}/access:
post:
operationId: accessSharedSecret
tags:
- Secret Sharing
description: Access a shared secret by its ID. If the secret is password protected, you must provide the password in the request body. Returns the secret value if access is granted, or an error if access is denied. The endpoint requires authentication if the shared secret is scoped to an organization.
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
password:
type: string
description: The password for accessing a password-protected shared secret. Only required if the secret is password protected.
additionalProperties: false
parameters:
- schema:
type: string
in: path
name: id
required: true
description: The ID of the shared secret to access.
responses:
'200':
description: Default Response
content:
application/json:
schema:
type: object
properties:
id:
type: string
expiresAt:
type: string
format: date-time
userId:
type: string
format: uuid
nullable: true
orgId:
type: string
format: uuid
nullable: true
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
expiresAfterViews:
type: number
nullable: true
accessType:
type: string
default: anyone
name:
type: string
nullable: true
lastViewedAt:
type: string
format: date-time
nullable: true
type:
type: string
default: share
authorizedEmails:
nullable: true
identityId:
type: string
format: uuid
nullable: true
allowExternalEmails:
type: boolean
default: false
nullable: true
orgName:
type: string
secretValue:
type: string
required:
- id
- expiresAt
- createdAt
- updatedAt
additionalProperties: false
'400':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 400
message:
type: string
error:
type: string
details: {}
required:
- reqId
- statusCode
- message
- error
additionalProperties: false
'401':
description: Default Response
content:
application/json:
schema:
type: object
properties:
reqId:
type: string
statusCode:
type: number
enum:
- 401
message:
type: string
error:
type: string
required:
- reqId
-
# --- truncated at 32 KB (34 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-secret-sharing-api-openapi.yml