systemd Credentials API

The Credentials API from systemd — 2 operation(s) for credentials.

Documentation

Specifications

Other Resources

OpenAPI Specification

systemd-credentials-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: systemd-hostnamed (org.freedesktop.hostname1) Boot Credentials API
  version: '1.0'
  summary: D-Bus API of systemd-hostnamed modeled as REST operations.
  description: 'Documentation/contract artifact for the `org.freedesktop.hostname1` D-Bus interface on the

    system bus. Manages the system hostname (static, transient, pretty), chassis type, deployment,

    location, icon name, and other machine info.

    '
  license:
    name: LGPL-2.1-or-later
    url: https://github.com/systemd/systemd/blob/main/LICENSES/LGPL-2.1-or-later.txt
servers:
- url: dbus://system/org.freedesktop.hostname1
tags:
- name: Credentials
paths:
  /io.systemd.Credentials/Encrypt:
    post:
      tags:
      - Credentials
      operationId: CredentialsEncrypt
      summary: Encrypt A Credential
      description: Calls `io.systemd.Credentials.Encrypt`. Wraps a secret with the system's encrypted-credentials key (TPM2 or host) for use as a `LoadCredentialEncrypted=` unit credential.
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
              - data
              properties:
                name:
                  type: string
                data:
                  type: string
                  contentEncoding: base64
                timestamp:
                  type: integer
                notAfter:
                  type: integer
      responses:
        '200':
          description: Encrypted blob.
          content:
            application/json:
              schema:
                type: object
                properties:
                  blob:
                    type: string
                    contentEncoding: base64
  /io.systemd.Credentials/Decrypt:
    post:
      tags:
      - Credentials
      operationId: CredentialsDecrypt
      summary: Decrypt A Credential
      description: Calls `io.systemd.Credentials.Decrypt`.
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
              - blob
              properties:
                name:
                  type: string
                blob:
                  type: string
                  contentEncoding: base64
                timestamp:
                  type: integer
      responses:
        '200':
          description: Decrypted plaintext.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: string
                    contentEncoding: base64