Kong Vaults API

Vault objects are used to configure different vault connectors for [managing secrets](https://developer.konghq.com/gateway/secrets-management/). Configuring a vault lets you reference secrets from other entities. This allows for a proper separation of secrets and configuration and prevents secret sprawl. For example, you could store a certificate and a key in a vault, then reference them from a certificate entity. This way, the certificate and key are not stored in the entity directly and are more secure. Secrets rotation can be managed using [TTLs](https://developer.konghq.com/gateway/entities/vault/).

OpenAPI Specification

kong-vaults-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.


    You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).

    Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: Kong Enterprise Admin ACLs Vaults API
  version: 3.14.0
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
security:
- adminToken: []
tags:
- description: 'Vault objects are used to configure different vault connectors for [managing secrets](https://developer.konghq.com/gateway/secrets-management/).

    Configuring a vault lets you reference secrets from other entities.

    This allows for a proper separation of secrets and configuration and prevents secret sprawl.

    <br><br>

    For example, you could store a certificate and a key in a vault, then reference them from a certificate entity. This way, the certificate and key are not stored in the entity directly and are more secure.

    <br><br>

    Secrets rotation can be managed using [TTLs](https://developer.konghq.com/gateway/entities/vault/).

    '
  name: Vaults
paths:
  /{workspace}/vaults:
    post:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Vault#create
      operationId: create-vault
      summary: Create a new Vault
      description: Create a new Vault
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the new Vault for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Vault'
      responses:
        '201':
          description: Successfully created Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Vaults
  /{workspace}/vaults/{VaultIdOrPrefix}:
    parameters:
    - $ref: '#/components/parameters/VaultIdOrPrefix'
    delete:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Vault#delete
      operationId: delete-vault
      summary: Delete a Vault
      description: Delete a Vault
      parameters:
      - $ref: '#/components/parameters/VaultIdOrPrefix'
      - $ref: '#/components/parameters/Workspace'
      responses:
        '204':
          description: Successfully deleted Vault or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Vaults
    get:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Vault#read
      operationId: get-vault
      summary: Get a Vault
      description: Get a Vault using ID or prefix.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      responses:
        '200':
          description: Successfully fetched Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault'
        '401':
          $ref: '#/components/responses/HTTP401Error'
        '404':
          description: Resource does not exist
      tags:
      - Vaults
    put:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Vault#update
      operationId: upsert-vault
      summary: Upsert a Vault
      description: Create or Update Vault using ID or prefix.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the Vault
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Vault'
      responses:
        '200':
          description: Successfully upserted Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Vaults
  /v2/control-planes/{controlPlaneId}/core-entities/vaults:
    parameters:
    - $ref: '#/components/parameters/controlPlaneId'
    get:
      operationId: list-vault
      summary: List all Vaults
      description: List all Vaults
      parameters:
      - $ref: '#/components/parameters/PaginationSize'
      - $ref: '#/components/parameters/PaginationOffset'
      - $ref: '#/components/parameters/PaginationTagsFilter'
      responses:
        '200':
          description: A successful response listing Vaults
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Vault_2'
                  next:
                    $ref: '#/components/schemas/PaginationNextResponse'
                  offset:
                    $ref: '#/components/schemas/PaginationOffsetResponse'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Vaults
    post:
      operationId: create-vault
      summary: Create a new Vault
      description: Create a new Vault
      requestBody:
        description: Description of the new Vault for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Vault_2'
      responses:
        '201':
          description: Successfully created Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Vaults
  /v2/control-planes/{controlPlaneId}/core-entities/vaults/{VaultId}:
    parameters:
    - $ref: '#/components/parameters/VaultId'
    - $ref: '#/components/parameters/controlPlaneId'
    delete:
      operationId: delete-vault
      summary: Delete a Vault
      description: Delete a Vault
      parameters:
      - $ref: '#/components/parameters/VaultId'
      responses:
        '204':
          description: Successfully deleted Vault or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Vaults
    get:
      operationId: get-vault
      summary: Get a Vault
      description: Get a Vault using ID or prefix.
      responses:
        '200':
          description: Successfully fetched Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
        '404':
          description: Resource does not exist
      tags:
      - Vaults
    put:
      operationId: upsert-vault
      summary: Upsert a Vault
      description: Create or Update Vault using ID or prefix.
      requestBody:
        description: Description of the Vault
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Vault_2'
      responses:
        '200':
          description: Successfully upserted Vault
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vault_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Vaults
components:
  responses:
    HTTP401Error_2:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
    HTTP401Error:
      description: Unauthorized
      content:
        application/json:
          examples:
            DuplicateApiKey:
              summary: Duplicate API key found
              value:
                message: Duplicate API key found
                status: 401
            InvalidAuthCred:
              summary: Invalid authentication credentials
              value:
                message: Unauthorized
                status: 401
            NoAPIKey:
              summary: No API key found
              value:
                message: No API key found in request
                status: 401
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
  parameters:
    PaginationSize:
      description: Number of resources to be returned.
      in: query
      name: size
      schema:
        type: integer
        default: 100
        maximum: 1000
        minimum: 1
    Workspace:
      description: The name of the workspace
      in: path
      name: workspace
      required: true
      schema:
        type: string
        example: team-payments
        default: default
    VaultId:
      description: ID of the Vault to lookup
      example: 9d4d6d19-77c6-428e-a965-9bc9647633e9
      in: path
      name: VaultId
      required: true
      schema:
        type: string
    PaginationOffset:
      allowEmptyValue: true
      description: Offset from which to return the next set of resources. Use the value of the 'offset' field from the response of a list operation as input here to paginate through all the resources
      in: query
      name: offset
      schema:
        type: string
    VaultIdOrPrefix:
      description: ID or prefix of the Vault to lookup
      example: 9d4d6d19-77c6-428e-a965-9bc9647633e9
      in: path
      name: VaultIdOrPrefix
      required: true
      schema:
        type: string
      x-speakeasy-match: id
    controlPlaneId:
      name: controlPlaneId
      in: path
      required: true
      schema:
        type: string
        format: uuid
        example: 9524ec7d-36d9-465d-a8c5-83a3c9390458
      description: The UUID of your control plane. This variable is available in the Konnect manager.
      x-speakeasy-param-force-new: true
    PaginationTagsFilter:
      allowEmptyValue: true
      description: A list of tags to filter the list of resources on. Multiple tags can be concatenated using ',' to mean AND or using '/' to mean OR.
      example: tag1,tag2
      in: query
      name: tags
      schema:
        type: string
  schemas:
    PaginationOffsetResponse:
      description: Offset is used to paginate through the API. Provide this value to the next list operation to fetch the next page
      type: string
    GatewayUnauthorizedError:
      type: object
      properties:
        message:
          type: string
        status:
          type: integer
      required:
      - message
      - status
    PaginationNextResponse:
      description: URI to the next page (may be null)
      type: string
    Vault:
      x-speakeasy-entity: Vault
      description: Vault entities are used to configure different Vault connectors. Examples of Vaults are Environment Variables, Hashicorp Vault and AWS Secrets Manager. Configuring a Vault allows referencing the secrets with other entities. For example a certificate entity can store a reference to a certificate and key, stored in a vault, instead of storing the certificate and key within the entity. This allows a proper separation of secrets and configuration and prevents secret sprawl.
      type: object
      properties:
        config:
          description: The configuration properties for the Vault which can be found on the vaults' documentation page.
          type: object
          additionalProperties: true
          nullable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        description:
          description: The description of the Vault entity.
          type: string
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        name:
          description: The name of the Vault that's going to be added. Currently, the Vault implementation must be installed in every Kong instance.
          type: string
        prefix:
          description: The unique prefix (or identifier) for this Vault configuration. The prefix is used to load the right Vault configuration and implementation when referencing secrets with the other entities.
          type: string
        tags:
          description: An optional set of strings associated with the Vault for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        config:
          prefix: ENV_PREFIX
        description: environment variable based vault
        id: 2747d1e5-8246-4f65-a939-b392f1ee17f8
        name: env
        prefix: env
        tags:
        - foo
        - bar
      additionalProperties: false
      required:
      - name
      - prefix
    Vault_2:
      description: Vault entities are used to configure different Vault connectors. Examples of Vaults are Environment Variables, Hashicorp Vault and AWS Secrets Manager. Configuring a Vault allows referencing the secrets with other entities. For example a certificate entity can store a reference to a certificate and key, stored in a vault, instead of storing the certificate and key within the entity. This allows a proper separation of secrets and configuration and prevents secret sprawl.
      type: object
      properties:
        config:
          description: The configuration properties for the Vault which can be found on the vaults' documentation page.
          type: object
          additionalProperties: true
          nullable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        description:
          description: The description of the Vault entity.
          type: string
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        name:
          description: The name of the Vault that's going to be added. Currently, the Vault implementation must be installed in every Kong instance.
          type: string
        prefix:
          description: The unique prefix (or identifier) for this Vault configuration. The prefix is used to load the right Vault configuration and implementation when referencing secrets with the other entities.
          type: string
        tags:
          description: An optional set of strings associated with the Vault for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        config:
          prefix: ENV_PREFIX
        description: environment variable based vault
        id: 2747d1e5-8246-4f65-a939-b392f1ee17f8
        name: env
        prefix: env
        tags:
        - foo
        - bar
      additionalProperties: false
      required:
      - name
      - prefix
  securitySchemes:
    adminToken:
      in: header
      name: Kong-Admin-Token
      type: apiKey
externalDocs:
  description: Documentation for Kong Gateway and its APIs
  url: https://developer.konghq.com