Infisical Secret Sharing API

The Secret Sharing API from Infisical — 3 operation(s) for secret sharing.

OpenAPI Specification

infisical-secret-sharing-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Infisical Admin Secret Sharing API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: Secret Sharing
paths:
  /api/v1/shared-secrets:
    get:
      operationId: listSharedSecrets
      tags:
      - Secret Sharing
      description: List all shared secrets created by the authenticated user or identity in their current organization.
      parameters:
      - schema:
          type: number
          minimum: 0
          maximum: 100
          default: 0
        in: query
        name: offset
        required: false
        description: The offset to start listing shared secrets from. Used for pagination.
      - schema:
          type: number
          minimum: 1
          maximum: 100
          default: 25
        in: query
        name: limit
        required: false
        description: The maximum number of shared secrets to return. Max is 100.
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secrets:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        expiresAt:
                          type: string
                          format: date-time
                        userId:
                          type: string
                          format: uuid
                          nullable: true
                        orgId:
                          type: string
                          format: uuid
                          nullable: true
                        createdAt:
                          type: string
                          format: date-time
                        updatedAt:
                          type: string
                          format: date-time
                        expiresAfterViews:
                          type: number
                          nullable: true
                        accessType:
                          type: string
                          default: anyone
                        name:
                          type: string
                          nullable: true
                        lastViewedAt:
                          type: string
                          format: date-time
                          nullable: true
                        type:
                          type: string
                          default: share
                        authorizedEmails:
                          nullable: true
                        identityId:
                          type: string
                          format: uuid
                          nullable: true
                        allowExternalEmails:
                          type: boolean
                          default: false
                          nullable: true
                      required:
                      - id
                      - expiresAt
                      - createdAt
                      - updatedAt
                      additionalProperties: false
                  totalCount:
                    type: number
                required:
                - secrets
                - totalCount
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    post:
      operationId: createSharedSecret
      tags:
      - Secret Sharing
      description: Create a new shared secret that can be accessed by a link.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  maxLength: 50
                  description: An optional name for the shared secret for easier identification.
                password:
                  type: string
                  description: An optional password to protect the shared secret. Recipients will need to provide this password to access the secret.
                secretValue:
                  type: string
                  maxLength: 10000
                  description: The secret value to share.
                expiresIn:
                  type: string
                  default: 30d
                  description: The duration after which the shared secret will expire. Accepts formats like '30d', '24h', '1w'. Maximum is 30 days, minimum is 5 minutes.
                maxViews:
                  type: number
                  minimum: 1
                  description: The maximum number of times the shared secret can be viewed before it expires. If not provided, unlimited views are allowed.
                accessType:
                  type: string
                  enum:
                  - anyone
                  - organization
                  default: organization
                  description: Determines who can access the shared secret. 'organization' restricts access to users within your organization. 'anyone' allows access to anyone with the link. Defaults to 'organization'.
                authorizedEmails:
                  type: array
                  items:
                    type: string
                    format: email
                  maxItems: 100
                  description: An optional array of email addresses to share the secret with. Maximum 100 emails. Organization members in the list get direct access. When allowExternalEmails is enabled, non-member emails are also accepted and recipients will receive the secret link via email, but must use the password to access it.
                allowExternalEmails:
                  type: boolean
                  description: When true, allows sharing with email addresses that do not belong to Infisical. A password is required when this option is enabled. External recipients will receive the secret link via email and must enter the password to access it.
              required:
              - secretValue
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  expiresAt:
                    type: string
                    format: date-time
                  userId:
                    type: string
                    format: uuid
                    nullable: true
                  orgId:
                    type: string
                    format: uuid
                    nullable: true
                  createdAt:
                    type: string
                    format: date-time
                  updatedAt:
                    type: string
                    format: date-time
                  expiresAfterViews:
                    type: number
                    nullable: true
                  accessType:
                    type: string
                    default: anyone
                  name:
                    type: string
                    nullable: true
                  lastViewedAt:
                    type: string
                    format: date-time
                    nullable: true
                  type:
                    type: string
                    default: share
                  authorizedEmails:
                    nullable: true
                  identityId:
                    type: string
                    format: uuid
                    nullable: true
                  allowExternalEmails:
                    type: boolean
                    default: false
                    nullable: true
                  sharedSecretLink:
                    type: string
                required:
                - id
                - expiresAt
                - createdAt
                - updatedAt
                - sharedSecretLink
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v1/shared-secrets/{id}:
    get:
      operationId: getSharedSecretById
      tags:
      - Secret Sharing
      description: Returns the full shared secret object without revealing the secret value. Authentication is required for shared secrets that are scoped to an organization.
      parameters:
      - schema:
          type: string
        in: path
        name: id
        required: true
        description: The ID of the shared secret to retrieve.
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  expiresAt:
                    type: string
                    format: date-time
                  userId:
                    type: string
                    format: uuid
                    nullable: true
                  orgId:
                    type: string
                    format: uuid
                    nullable: true
                  createdAt:
                    type: string
                    format: date-time
                  updatedAt:
                    type: string
                    format: date-time
                  expiresAfterViews:
                    type: number
                    nullable: true
                  accessType:
                    type: string
                    default: anyone
                  name:
                    type: string
                    nullable: true
                  lastViewedAt:
                    type: string
                    format: date-time
                    nullable: true
                  type:
                    type: string
                    default: share
                  identityId:
                    type: string
                    format: uuid
                    nullable: true
                  isPasswordProtected:
                    type: boolean
                    description: Whether the shared secret is protected by a password.
                  isAuthorizedUser:
                    type: boolean
                    description: Whether the current user is an authorized org member. If false, the user must provide a password.
                required:
                - id
                - expiresAt
                - createdAt
                - updatedAt
                - isPasswordProtected
                - isAuthorizedUser
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    delete:
      operationId: deleteSharedSecret
      tags:
      - Secret Sharing
      description: Delete a shared secret by its ID.
      parameters:
      - schema:
          type: string
        in: path
        name: id
        required: true
        description: The ID of the shared secret to delete.
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  expiresAt:
                    type: string
                    format: date-time
                  userId:
                    type: string
                    format: uuid
                    nullable: true
                  orgId:
                    type: string
                    format: uuid
                    nullable: true
                  createdAt:
                    type: string
                    format: date-time
                  updatedAt:
                    type: string
                    format: date-time
                  expiresAfterViews:
                    type: number
                    nullable: true
                  accessType:
                    type: string
                    default: anyone
                  name:
                    type: string
                    nullable: true
                  lastViewedAt:
                    type: string
                    format: date-time
                    nullable: true
                  type:
                    type: string
                    default: share
                  authorizedEmails:
                    nullable: true
                  identityId:
                    type: string
                    format: uuid
                    nullable: true
                  allowExternalEmails:
                    type: boolean
                    default: false
                    nullable: true
                required:
                - id
                - expiresAt
                - createdAt
                - updatedAt
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v1/shared-secrets/{id}/access:
    post:
      operationId: accessSharedSecret
      tags:
      - Secret Sharing
      description: Access a shared secret by its ID. If the secret is password protected, you must provide the password in the request body. Returns the secret value if access is granted, or an error if access is denied. The endpoint requires authentication if the shared secret is scoped to an organization.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                password:
                  type: string
                  description: The password for accessing a password-protected shared secret. Only required if the secret is password protected.
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: id
        required: true
        description: The ID of the shared secret to access.
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  expiresAt:
                    type: string
                    format: date-time
                  userId:
                    type: string
                    format: uuid
                    nullable: true
                  orgId:
                    type: string
                    format: uuid
                    nullable: true
                  createdAt:
                    type: string
                    format: date-time
                  updatedAt:
                    type: string
                    format: date-time
                  expiresAfterViews:
                    type: number
                    nullable: true
                  accessType:
                    type: string
                    default: anyone
                  name:
                    type: string
                    nullable: true
                  lastViewedAt:
                    type: string
                    format: date-time
                    nullable: true
                  type:
                    type: string
                    default: share
                  authorizedEmails:
                    nullable: true
                  identityId:
                    type: string
                    format: uuid
                    nullable: true
                  allowExternalEmails:
                    type: boolean
                    default: false
                    nullable: true
                  orgName:
                    type: string
                  secretValue:
                    type: string
                required:
                - id
                - expiresAt
                - createdAt
                - updatedAt
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - 

# --- truncated at 32 KB (34 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-secret-sharing-api-openapi.yml