Trust Protection Foundation WebSDK (Venafi Trust Protection Platform)

The self-hosted Venafi / CyberArk Trust Protection Foundation Web SDK, version 26.1.1. 388 operations across 364 paths covering certificate management, discovery, identity and permissions, OAuth application/scope administration (/vedauth, /vedsdk/oauth), SSH certificates and authorized keys, code signing and HSM, SecretStore, flows, recycle bin, processing engines, statistics and system status. Because the product is customer-installed, the contract publishes a templated server (https://{dnsname}/) rather than a vendor host.

Operations 389

Showing the first 250 of 389. The full set is in the contract, and via get_provider_operations.

POST /vedsdk/pki/hashicorp/role/ Create a role #
DELETE /vedsdk/pki/hashicorp/role/{guid} Remove policy enforcement settings #
GET /vedsdk/pki/hashicorp/role/{guid} Retrieve policy information #
PUT /vedsdk/pki/hashicorp/role/{guid} Update Trust Protection Foundation info #
POST /vedsdk/pki/hashicorp/ca/{guid} Create or update roles #
GET /vedsdk/pki/hashicorp/ca/{guid} Retrieve details #
PUT /vedsdk/pki/hashicorp/ca/{guid} Update configuration #
DELETE /vedsdk/pki/hashicorp/ca/{guid} Remove PKI configuration #
POST /vedsdk/pki/hashicorp/ca/{guid}/renew Initiate renewal or first time enrollment #
POST /vedsdk/pki/hashicorp/ca/ Define configuration #
GET /vedsdk/pki/hashicorp/ca/ List all HashiCorp Vault PKI secrets #
POST /vedauth/authorize/device Request a device grant #
POST /vedauth/authorize/oauth Request a grant with user credentials. #
POST /vedauth/authorize/integrated Request a grant via NTLM/Kerberos #
POST /vedauth/authorize/certificate Request a grant via certificate #
POST /vedauth/authorize/jwt Request a grant via JWT #
POST /vedauth/authorize/token Refresh a bearer/device token #
GET /vedauth/authorize/verify Verify bearer token validity #
GET /vedauth/authorize/IsAuthServer Verify server availability #
GET /vedauth/revoke/token Revoke grant #
POST /vedsdk/certificates/Retrieve/{vaultId} Retrieve a certificate by vault ID #
GET /vedsdk/certificates/Retrieve/{vaultId} Retrieve a certificate by vault ID (GET) #
GET /vedsdk/certificates/{guid}/PreviousVersions Get archived certificates #
POST /vedsdk/certificates/Validate Validate a deployed certificate #
PUT /vedsdk/certificates/{guid} Set or update certificate attributes #
GET /vedsdk/certificates/{guid} Get certificate details #
DELETE /vedsdk/certificates/{guid} Delete a certificate #
POST /vedsdk/certificates/CheckPolicy Check policy compliance #
POST /vedsdk/certificates/Request Enroll or provision a certificate #
POST /vedsdk/certificates/Retrieve Retrieve an issued certificate #
GET /vedsdk/certificates/Retrieve Retrieve an issued certificate (GET) #
POST /vedsdk/certificates/Renew Renew a certificate #
POST /vedsdk/certificates/Revoke Revoke a certificate #
GET /vedsdk/certificates/ Search certificates #
HEAD /vedsdk/certificates/ Get certificates count #
POST /vedsdk/certificates/Associate Associate an application #
POST /vedsdk/certificates/Dissociate Dissociate an application #
POST /vedsdk/certificates/Push Initiate provisioning #
POST /vedsdk/certificates/Import Import a certificate #
POST /vedsdk/certificates/Reset Reset processing state #
POST /vedsdk/certificates/Retry Retry processing #
GET /vedsdk/certificates/{guid}/ValidationResults Retrieve certificate validation results #
POST /vedsdk/discovery/Import Import certificates #
DELETE /vedsdk/discovery/{guid} Delete a discovery job #
POST /vedsdk/codesign/FindEnvironment Find Environment #
POST /vedsdk/codesign/CreateEnvironment Create Environment #
POST /vedsdk/codesign/DeleteEnvironment Delete Environment #
POST /vedsdk/codesign/GetEnvironment Get Environment #
POST /vedsdk/codesign/RenewEnvironment Renew Environment #
POST /vedsdk/codesign/UpdateEnvironment Update Environment #
POST /vedsdk/codesign/EnumerateProjects Get Projects #
POST /vedsdk/codesign/GetProject Get Project #
POST /vedsdk/codesign/CreateProject Create Project #
POST /vedsdk/codesign/UpdateProject Update Project #
POST /vedsdk/codesign/UpdateProjectStatus Update Project Status #
POST /vedsdk/codesign/DeleteProject Delete Project #
POST /vedsdk/codesign/RenameProject Rename Project #
POST /vedsdk/codesign/EnumerateTemplates Get Templates #
POST /vedsdk/codesign/GetTemplate Get Template #
POST /vedsdk/codesign/CreateTemplate Create Template #
POST /vedsdk/codesign/UpdateTemplate Update Template #
POST /vedsdk/codesign/DeleteTemplate Delete Template #
POST /vedsdk/codesign/RenameTemplate Rename Template #
POST /vedsdk/codesign/EnumerateApplications Get Applications #
POST /vedsdk/codesign/GetApplication Get Application #
POST /vedsdk/codesign/CreateApplication Create Application #
POST /vedsdk/codesign/UpdateApplication Update Application #
POST /vedsdk/codesign/DeleteApplication Delete Application #
POST /vedsdk/codesign/RenameApplication Rename Application #
POST /vedsdk/codesign/CountReferences Get Application Reference Count #
POST /vedsdk/codesign/EnumerateReferences Get Application Reference #
POST /vedsdk/codesign/EnumerateApplicationCollections Get All Applications Collections #
POST /vedsdk/codesign/GetApplicationCollection Get Application Collections Info #
POST /vedsdk/codesign/GetApplicationCollectionMemberDNs Get Application Collection Member DNs #
POST /vedsdk/codesign/GetApplicationCollectionMembers Get Members of Application Collection #
POST /vedsdk/codesign/CreateApplicationCollection Create Application Collection #
POST /vedsdk/codesign/UpdateApplicationCollection Update Application Collection #
POST /vedsdk/codesign/DeleteApplicationCollection Delete Application Collection #
POST /vedsdk/codesign/RenameApplicationCollection Rename Application Collection #
GET /vedsdk/codesign/GetGlobalConfiguration Get Global Configuration #
POST /vedsdk/codesign/SetGlobalConfiguration Set Global Configuration #
POST /vedsdk/codesign/AddAdministrator Assign Admin Rights to Trustee #
POST /vedsdk/codesign/RemoveAdministrator Remove Admin Rights from Trustee #
POST /vedsdk/codesign/AddApplicationAdministrator Add Application Admin Rights #
POST /vedsdk/codesign/RemoveApplicationAdministrator Remove Application Admin Rights #
POST /vedsdk/codesign/AddProjectApprover Add Project Approver #
POST /vedsdk/codesign/RemoveProjectApprover Remove Project Approver #
POST /vedsdk/codesign/GetRight Get Caller Rights for Project #
POST /vedsdk/codesign/GetTrusteeRights Get Trustee Rights #
POST /vedsdk/codesign/GetObjectRights Get Object Rights #
POST /vedsdk/codesign/AddPreApproval Add Flow Staging Information for a Pre-Approval #
POST /vedsdk/codesign/RunMacro Run Macro Info #
POST /vedsdk/codesign/RetrieveArchiveEntries Retrieve Sign Archive Entries #
POST /vedsdk/codesign/ExportSignArchive Exports Sign Archive Entries #
GET /vedsdk/codesign/ExportSignArchive Exports Sign Archive Entries, no filtering #
POST /vedsdk/actions/codesign/prequalify/Create Pre-qualify approval flow #
POST /vedsdk/credentials/adaptable/create Create Adaptable credential #
POST /vedsdk/credentials/adaptable/update Update Adaptable credential #
POST /vedsdk/credentials/cyberark/create Create CyberArk credential #
POST /vedsdk/credentials/cyberark/update Update CyberArk credential. #
POST /vedhsm/api/signjwt Signs JSON Web Token #
GET /vedhsm/api/IsHsm Verify HSM Server Info #
POST /vedhsm/api/sign Sign Data #
POST /vedhsm/api/decrypt Decrypts Data #
POST /vedhsm/api/derive Derives a Key #
POST /vedhsm/api/getgpgpublickey Get GPG public key #
POST /vedhsm/api/storeobject Stores a key within an environment #
POST /vedhsm/api/getchain Get Certificate Chain #
POST /vedhsm/api/getobjects Get Objects #
POST /vedhsm/api/csctelemetry Code Sign Client Telemetry #
GET /vedscim/{owner}/available Get provider-specific SCIM endpoint status #
GET /vedscim/available Get SCIM Server endpoint status #
GET /vedsdk/client/ Search client records #
GET /vedsdk/client/details/ Search client records (details) #
POST /vedsdk/client/delete Delete client records #
GET /vedsdk/client/work/ Get own work #
POST /vedsdk/algorithmselector/get Get the algorithm configured for an object #
POST /vedsdk/algorithmselector/commit Set the algorithm configured for an object #
POST /vedsdk/algorithmselector/find Find algorithm selectors for a specific security strength #
POST /vedsdk/algorithmselector/getpolicy Get the allowed algorithms for a container #
POST /vedsdk/algorithmselector/commitpolicy Set the allowed algorithms for a container #
POST /vedsdk/algorithmselector/getselector Get details about an algorithm #
POST /vedsdk/algorithmselector/getallselectors Get all algorithms #
POST /vedsdk/algorithmselector/getallowedalgorithms Get allowed algorithms for an object #
POST /vedsdk/algorithmselector/getglobalalgorithms Get the globally allowed algorithms #
POST /vedsdk/algorithmselector/setglobalalgorithms Set the globally allowed algorithms #
POST /vedsdk/flow/tickets/enumerate Enumerate pending tickets. #
POST /vedsdk/flow/tickets/enumerateapproved Enumerate approved and still in use tickets. #
POST /vedsdk/flow/tickets/approve Approve one or more pending tickets. #
POST /vedsdk/flow/tickets/reject Reject one or more pending tickets. #
POST /vedsdk/flow/tickets/count Count pending tickets. #
POST /vedsdk/flow/tickets/countapproved Count approved tickets. #
POST /vedsdk/flow/tickets/load Load a single ticket #
POST /vedsdk/flow/tickets/update Update existing approval #
GET /vedsdk/serverstatus/idle Check if idle #
GET /vedsdk/serverstatus/active Check if active #
GET /vedsdk/SystemStatus/ Get all engines #
GET /vedsdk/SystemStatus/Version Get engine schema version #
GET /vedsdk/SystemStatus/Upgrade/Status Get upgrade status #
GET /vedsdk/SystemStatus/Upgrade/Summary Get upgrade summary #
GET /vedsdk/SystemStatus/Upgrade/Engine Get the upgrade status of one engine #
GET /vedsdk/SystemStatus/Upgrade/Engines Get all engine upgrade statuses #
GET /vedsdk/SystemStatus/Upgrade/History Get upgrade history #
POST /vedsdk/BusStatus/getstatus Request bus participant status #
POST /vedsdk/BusStatus/getmeshdnsname Get mesh partner DNS name #
POST /vedsdk/BusStatus/setmeshdnsname Set mesh partner DNS name #
GET /vedsdk/preferences/ Get user preferences #
POST /vedsdk/preferences/ Add user preference #
DELETE /vedsdk/preferences/ Clear user preference #
POST /vedsdk/recyclebin/getcontents Retrieve deleted items #
POST /vedsdk/recyclebin/getitem Retrieve deleted item #
POST /vedsdk/recyclebin/getitemdetails Retrieve deleted item details #
POST /vedsdk/recyclebin/restore Restore deleted item #
POST /vedsdk/recyclebin/purge Purge deleted item #
POST /vedsdk/recyclebin/empty Purge all items #
POST /vedsdk/recyclebin/setconfiguration Set recyclebin configuration #
POST /vedsdk/recyclebin/getconfiguration Get recyclebin configuration #
POST /vedsdk/recyclebin/purgetask Start/stop background purge #
POST /vedsdk/recyclebin/deletiontask Start/stop deletion task #
POST /vedsdk/oauth/grantrole Assign a role #
POST /vedsdk/oauth/revokerole Remove a role #
POST /vedsdk/oauth/listroles Get assigned roles #
POST /vedsdk/oauth/getrole Get own role #
POST /vedsdk/oauth/getconfiguration Get configuration #
POST /vedsdk/oauth/setconfiguration Set configuration #
POST /vedsdk/oauth/createapplication Create an application #
POST /vedsdk/oauth/enumerateapplications Enumerate all applications #
POST /vedsdk/oauth/getapplications Search applications #
POST /vedsdk/oauth/getapplication Get an application #
POST /vedsdk/oauth/updateapplication Update an application #
POST /vedsdk/oauth/deleteapplication Delete an application #
POST /vedsdk/oauth/getscopes Get all scopes #
POST /vedsdk/oauth/getgrants Get grants issued to an identity #
POST /vedsdk/oauth/enumerategrants Enumerate all application grants #
POST /vedsdk/oauth/revokegrants Revoke grants #
POST /vedsdk/oauth/createrule Create a rule #
POST /vedsdk/oauth/getrules Search rules #
POST /vedsdk/oauth/enumeraterules Enumerate all rules #
POST /vedsdk/oauth/updaterule Update a rule #
POST /vedsdk/oauth/deleterule Delete a rule #
POST /vedsdk/oauth/deleterules Deletes rules #
POST /vedsdk/oauth/grantcount Get grant count #
POST /vedsdk/oauth/usercount Get user count #
POST /vedsdk/oauth/createjwtmapping Create JWT mapping #
POST /vedsdk/oauth/enumeratejwtmappings Enumerate JWT mappings #
POST /vedsdk/oauth/getjwtmappings Search JWT mappings #
POST /vedsdk/oauth/getjwtmapping Get JWT mapping #
POST /vedsdk/oauth/updatejwtmapping Update JWT mapping #
POST /vedsdk/oauth/deletejwtmapping Delete JWT mapping #
POST /vedsdk/stats/createcounter Create a counter #
POST /vedsdk/stats/deletecounter Delete a counter #
POST /vedsdk/stats/renamecounter Rename a counter #
POST /vedsdk/stats/updatecounter Update a counter #
POST /vedsdk/stats/getcounter Get a counter #
POST /vedsdk/stats/getcounters Get all counters #
POST /vedsdk/stats/countercontainers Get containers #
POST /vedsdk/stats/query Get values #
POST /vedsdk/stats/querytags Search tags #
GET /vedsdk/processingengines/ Get all processing engines #
GET /vedsdk/processingengines/folder/{folderGuid} Get restrictions for a folder #
PUT /vedsdk/processingengines/folder/{folderGuid} Update restriction #
DELETE /vedsdk/processingengines/folder/{folderGuid} Clear all restrictions on a folder #
GET /vedsdk/processingengines/engine/{engineGuid} Get restrictions for an engine #
POST /vedsdk/processingengines/engine/{engineGuid} Add a new restriction #
DELETE /vedsdk/processingengines/folder/{folderGuid}/{engineGuid} Remove one engine from restriction on a folder #
POST /vedsdk/permissions/getprincipals Get trustees #
POST /vedsdk/permissions/getpermissions Get assigned permissions #
POST /vedsdk/permissions/geteffectivepermissions Get effective permissions #
POST /vedsdk/permissions/grantpermissions Grant permissions #
POST /vedsdk/permissions/revokepermissions Revoke permissions #
POST /vedsdk/permissions/replacepermissions Update permissions #
GET /vedsdk/permissions/refresh Refresh permissions #
GET /vedsdk/permissions/object/{guid} Gets object trustees #
GET /vedsdk/permissions/object/{guid}/local/{identity} Get assigned permissions of a local identity #
GET /vedsdk/permissions/object/{guid}/local/{identity}/effective Get effective permissions of local identity #
GET /vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal} Get assigned permissions of an identity #
DELETE /vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal} Delete permissions #
POST /vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal} Add permissions #
PUT /vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal} Update permissions #
GET /vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}/effective Get effective permissions of an identity #
GET /vedsdk/permissions/object/{guid}/myeffective Gets the effective permissions of the session's user for the given object. #
DELETE /vedsdk/permissions/object/{guid}/local/{principal} Delete permissions #
POST /vedsdk/permissions/object/{guid}/local/{principal} Add permissions #
PUT /vedsdk/permissions/object/{guid}/local/{principal} Update permissions #
POST /vedsdk/config/enumerate Search objects #
POST /vedsdk/config/enumerateall Enumerate objects #
POST /vedsdk/config/enumeratepolicies Enumerate policies #
POST /vedsdk/config/enumerateobjectsderivedfrom Enumerate derived objects #
POST /vedsdk/config/create Create an object #
POST /vedsdk/config/delete Delete an object #
GET /vedsdk/config/defaultdn Gets the default DN #
POST /vedsdk/config/find Search an object by attribute #
POST /vedsdk/config/readall Read all attributes #
POST /vedsdk/config/findcontainers Search containers #
POST /vedsdk/config/findobjectsofclass Search objects of class #
POST /vedsdk/config/findpolicy Search policies #
POST /vedsdk/config/gethighestrevision Get highest container revision #
POST /vedsdk/config/getrevision Get object revision #
POST /vedsdk/config/getobjecttrustees Get trustees of object #
POST /vedsdk/config/guidtodn Convert GUID to DN #
POST /vedsdk/config/isvalid Check if object exists #
POST /vedsdk/config/mutateobject Change object class #
POST /vedsdk/config/containableclasses Enumerate container classes #
POST /vedsdk/config/dntoguid Convert DN to GUID #
POST /vedsdk/config/idinfo Convert ID to DN #
POST /vedsdk/config/renameobject Rename an object #
POST /vedsdk/config/clearattribute Remove an attribute #
POST /vedsdk/config/clearpolicyattribute Remove a policy attribute #
POST /vedsdk/config/read Read an attribute #
POST /vedsdk/config/countobjects Return number of objects #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/trust-protection-foundation-websdk"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

venafi-trust-protection-foundation-websdk-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Trust Protection Foundation  WebSDK
  description: "\r\n# Introduction\r\nThe Trust Protection Foundation Web SDK is a subset of REST APIs that allow you to:\r\
    \n  * Automate certificate management\r\n  * Integrate with DevOps processes\r\n  * Discover machine identities\r\n  *\
    \ Extract data to integrate with data warehouses\r\n  * Perform bulk actions\r\n  * Set up and administer Trust Protection\
    \ Foundation\r\n  * Onboard teams\r\n  * Create custom, automated business logic and flows between internal systems\r\n\
    \r\nAll these use cases can be accomplished using the Trust Protection Foundation REST API. Most Web SDK calls require\
    \ you to pass a bearer token in the header.\r\n\r\n[Getting started](https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php)\
    \ provides information about how to setup the Web SDK. This section includes several examples of the most \r\ncommon integration\
    \ tasks. If you are new to developing on the CyberArk Trust Protection Foundation, you should begin here.\r\n\r\n\n\n\
    > ℹ️ **Looking for the legacy WebSDK Developer's Guide?** [View the 26.1 legacy WebSDK Developer's Guide](../26.1/TopNav/Content/SDK/WebSDK/c-sdk-AboutThisGuide.php).\n\
    \n# Web SDK best practices\r\nWe recommend the following best practices to improve the capability of the Web SDK:\r\n\r\
    \n  * If you are implementing our APIs for the first time, be sure to follow the setup details in Getting started with\
    \ automation.\r\n  * Review and grant the API caller the necessary permissions that match your API calls. You can use\
    \ the API descriptions in \r\nthis guide to refine caller permissions. \r\n  * Whenever you get an unexpected result,\
    \ carefully check the API call and JSON payload. Unless otherwise specified:\r\n    * API method names evaluate as case\
    \ insensitive.\r\n    * Parameter names and values evaluate as case sensitive.\r\n    * Extra parameters may be ignored.\r\
    \n    * Invalid syntax, data, or parameters generate errors.\r\n  * Apply the same naming standard whenever you create\
    \ any new object.\r\n  * Adopt a standard convention for avoiding device and certificate name collisions. Collisions can\
    \ occur when the name you define already exists in a CyberArk product. You can use the same prefix or suffix, and then\
    \ add something unique to the name. Suppose you are defining an object for a company called SW Banking, you could prepend\
    \ SW to the start of the name. For example, SWDeviceObject.\r\n  * Assign the credentials to a Policy folder that contains\
    \ multiple devices. The policy credentials allow multiple devices to use the same credential.\r\n  * Reuse Credential\
    \ objects wherever standardization is possible to avoid creating extraneous objects.\r\n  * To view API changes in the\
    \ UI, be sure to refresh the contents of the page.\r\n  * Use the event log to audit and troubleshoot API calls. A list\
    \ of Web SDK event definitions appears in the Logging tree. Not every API method logs events. However, Web SDK and other\
    \ events that occur appear on the General Log tab of a Policy folder or in the MMC Event Viewer snap-in."
  version: 26.1.1
servers:
- url: /
  description: Current Host
- url: https://REPLACEdnsnameME/
  description: System
- url: https://{dnsname}/
  description: Configurable Hostname
  variables:
    dnsname:
      default: localhost
      description: Production API Hostname
paths:
  /vedsdk/pki/hashicorp/role/:
    post:
      tags:
      - HashiCorp PKI APIs
      summary: Create a role
      description: "Create a role in Trust Protection Foundation.\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiRoles_Create
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreateRoleRequest_'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreateRoleResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
  /vedsdk/pki/hashicorp/role/{guid}:
    delete:
      tags:
      - HashiCorp PKI APIs
      summary: Remove policy enforcement settings
      description: "Remove policy enforcement settings for a HashiCorp Vault PKI role from Trust Protection Foundation.\r\n\
        \r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiRoles_Delete
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreateRoleResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    get:
      tags:
      - HashiCorp PKI APIs
      summary: Retrieve policy information
      description: "Retrieve policy information from Trust Protection Foundation about a HashiCorp Vault PKI role.\r\n\r\n\
        _Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiRoles_GetByGuid
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_Role'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    put:
      tags:
      - HashiCorp PKI APIs
      summary: Update Trust Protection Foundation info
      description: "Update Trust Protection Foundation information about a HashiCorp role.\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiRoles_Update
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreateRoleResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    parameters:
    - name: guid
      in: path
      description: ''
      required: true
      schema:
        type: string
  /vedsdk/pki/hashicorp/ca/{guid}:
    post:
      tags:
      - HashiCorp PKI APIs
      summary: Create or update roles
      description: "Create or update roles in the HashiCorp Vault PKI secrets engine according to the Trust Protection Foundation\
        \ configuration.\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_EnforceRoles
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    get:
      tags:
      - HashiCorp PKI APIs
      summary: Retrieve details
      description: "Retrieve details about a HashiCorp Vault PKI secrets engine.\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_GetByGuid
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_PkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    put:
      tags:
      - HashiCorp PKI APIs
      summary: Update configuration
      description: "Update configuration for a HashiCorp Vault PKI secrets engine that is managed by Trust Protection Foundation.\r\
        \n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_Update
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    delete:
      tags:
      - HashiCorp PKI APIs
      summary: Remove PKI configuration
      description: "Remove configuration for managing a HashiCorp Vault PKI secrets engine from Trust Protection Foundation.\r\
        \n\r\n_Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_Delete
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    parameters:
    - name: guid
      in: path
      description: ''
      required: true
      schema:
        type: string
  /vedsdk/pki/hashicorp/ca/{guid}/renew:
    post:
      tags:
      - HashiCorp PKI APIs
      summary: Initiate renewal or first time enrollment
      description: "Initiate renewal or first time enrollment of a HashiCorp Vault PKI intermediate CA certificate.\r\n\r\n\
        _Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_EnrollAndProvision
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    parameters:
    - name: guid
      in: path
      description: ''
      required: true
      schema:
        type: string
  /vedsdk/pki/hashicorp/ca/:
    post:
      tags:
      - HashiCorp PKI APIs
      summary: Define configuration
      description: "Define configuration for Trust Protection Foundation to manage the intermediate CA certificate.\r\n\r\n\
        _Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_Create
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiRequest'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_CreatePkiResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
    get:
      tags:
      - HashiCorp PKI APIs
      summary: List all HashiCorp Vault PKI secrets
      description: "List all HashiCorp Vault PKI secrets engines that are managed by Trust Protection Foundation.\r\n\r\n\
        _Required scope: certificate_"
      operationId: Venafi_Drivers_Applications_HashiCorp_HashiCorpPkiConfiguration_Get
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Drivers_Applications_HashiCorp_REST_Pkis'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
  /vedauth/authorize/device:
    post:
      tags:
      - Authentication Server APIs
      summary: Request a device grant
      description: "Triggers a grant request via device authorization flow (See RFC 8628 Section 3.1)\r\n\r\n_Required scope:\
        \ Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_RequestDeviceAuth
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthRequest_device'
        required: true
      responses:
        '200':
          description: Grant issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse_device'
        '400':
          description: Grant issuance denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthError'
  /vedauth/authorize/oauth:
    post:
      tags:
      - Authentication Server APIs
      summary: Request a grant with user credentials.
      description: "\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_AuthorizeOAuth
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthRequest_oauth'
        required: true
      responses:
        '200':
          description: Grant issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse_oauth'
        '400':
          description: Grant issuance denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthError'
  /vedauth/authorize/integrated:
    post:
      tags:
      - Authentication Server APIs
      summary: Request a grant via NTLM/Kerberos
      description: "\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_IntegratedAuthorize
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthRequest_integrated'
        required: true
      responses:
        '200':
          description: Grant issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse_integrated'
        '400':
          description: Grant issuance denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthError'
  /vedauth/authorize/certificate:
    post:
      tags:
      - Authentication Server APIs
      summary: Request a grant via certificate
      description: "\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_CertificateAuthorize
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthRequest_certificate'
        required: true
      responses:
        '200':
          description: Grant issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse_certificate'
        '400':
          description: Grant issuance denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthError'
  /vedauth/authorize/jwt:
    post:
      tags:
      - Authentication Server APIs
      summary: Request a grant via JWT
      description: "\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_JwtAuthorize
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthRequest_jwt'
        required: true
      responses:
        '200':
          description: Grant issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse_jwt'
        '400':
          description: Grant issuance denied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthError'
  /vedauth/authorize/token:
    post:
      tags:
      - Authentication Server APIs
      summary: Refresh a bearer/device token
      description: "This endpoint supports refreshing bearer tokens as well as device access tokens (OAuth 2.0 Device Authorization\
        \ Grant).\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_Token
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Web_SDK_Authentication_TokenOAuthRequest'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeOAuthResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
  /vedauth/authorize/verify:
    get:
      tags:
      - Authentication Server APIs
      summary: Verify bearer token validity
      description: "\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_VerifyToken
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_AuthorizeVerifyResponse'
        '403':
          description: ' The API requires a scope not granted to the provided access token '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '400':
          description: ' Missing or invalid request property. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
        '401':
          description: ' A valid access token is required. '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Web_SDK_Authentication_OAuthError'
      security:
      - AccessToken: []
  /vedauth/authorize/IsAuthServer:
    get:
      tags:
      - Authentication Server APIs
      summary: Verify server availability
      description: "This endpoint can be used by a client to ensure the auth server is running before attempting to perform\
        \ grant tasks\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Authorize_IsAuthServer
      responses:
        '200':
          description: Server available
      security:
      - AccessToken: []
  /vedauth/revoke/token:
    get:
      tags:
      - Authentication Server APIs
      summary: Revoke grant
      description: "Revokes the grant passed in via a bearer token in the header\r\n\r\n_Required scope: Any_"
      operationId: Venafi_Web_SDK_Authentication_Revoke_RevokeGrant
      responses:
        '200':
          description: Grant revoked
        '202':
          description: Grant revocation failed
      security:
      - AccessToken: []
  /vedsdk/certificates/Retrieve/{vaultId}:
    post:
      tags:
      - Certificate Management APIs
      summary: Retrieve a certificate by vault ID
      description: "Returns the available certificate data and optional private key information for an enrolled or archived\
        \ certificate by its Vault Id.\r\nThe format property of the request allows to choose the following formats of the\
        \ returned certificate binary data:\r\n* Base64\r\n* Base64 (PKCS #8)\r\n* DER\r\n* JKS:\r\n* PKCS #7\r\n* PKCS #12\r\
        \n\r\n_Required scope: certificate:manage_"
      operationId: Venafi_WebSDK_CertificateRequest_CertificateRequestRest_CertificateRetrieveByVaultId
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WebSDK_CertificateRequest_RetrieveByVaultIdRequest_Retrieve__vaultId_'
        required: true
      responses:
        '200':
          description: Certificate retrieved successfully. The response body contains the certificate data and optional private
            key information.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebSDK_CertificateRequest_RetrieveResponse_Retrieve__vaultId_'
        '400':
          description: Invalid or missing request parameters. The Error property contains details about the failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebSDK_CertificateRequest_RetrieveResponse'
      security:
      - AccessToken: []
    get:
      tags:
      - Certificate Management APIs
      summary: Retrieve a certificate by vault ID (GET)
      description: "Returns the available certificate data and optional private key information for an enrolled or archived\
        \ certificate by its Vault Id.\r\nThe format property of the request allows to choose the following formats for the\
        \ returned data:\r\n\r\n| Format           | Response Content Type            |\r\n| ---------------- | --------------------------------\
        \ |\r\n| Base64           | application/x-pem-file           |\r\n| Base64 (PKCS #8) | application/x-pem-file    \
        \       |\r\n| DER              | application/x-x509-ca-cert       |\r\n| JKS              | application/octet-stream\
        \         |\r\n| PKCS #7          | application/x-pkcs7-certificates |\r\n| PKCS #12         | application/x-pkcs12\
        \             |\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_WebSDK_CertificateRequest_CertificateRequestRest_CertificateRetrieveByVaultIdGet
      parameters:
      - name: Format
        in: query
        schema:
          type: string
      - name: Password
        in: query
        schema:
          type: string
      - name: IncludePrivateKey
        in: query
        schema:
          type: string
      - name: IncludeChain
        in: query
        schema:
          type: string
      - name: RootFirstOrder
        in: query
        schema:
          type: string
      - name: FriendlyName
        in: query
        schema:
          type: string
      - name: KeystorePassword
        in: query
        schema:
          type: string
      - name: EncryptionAlgorithm
        in: query
        schema:
          type: string
      responses:
        '200':
          description: Returns the certificate as a binary stream.
          content:
            application/octet-stream:
              schema:
                $ref: '#/components/schemas/IO_Stream'
        '202':
          description: The certificate issuance is still pending. Use the /certificate/retrieve endpoint to obtain the certificate
            after it is issued.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IO_Stream'
        '500':
          description: An internal error occurred during certificate retrieval processing. See the error message for details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IO_Stream'
        '400':
          description: ' Invalid or missing request parameters. See the error message for details.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IO_Stream'
      security:
      - AccessToken: []
    parameters:
    - name: vaultId
      in: path
      description: The certificate data Vault Id.
      required: true
      schema:
        type: string
  /vedsdk/certificates/{guid}/PreviousVersions:
    get:
      tags:
      - Certificate Management APIs
      summary: Get archived certificates
      description: "Retrieves the archived versions of a certificate identified by its GUID. \r\nThe request can include query\
        \ parameters to exclude expired or revoked certificates from the results. \r\nThe response contains a list of previous\
        \ certificate versions, each with detailed information about the certificate.\r\n\r\n_Required scope: certificate_"
      operationId: Venafi_WebSDK_CertificateRequest_CertificateRequestRest_CertificatePreviousVersions
      parameters:
      - name: ExcludeExpired
        in: query
        description: Exclude expired certificates
  

# --- truncated at 32 KB (2522 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/openapi/venafi-trust-protection-foundation-websdk-openapi.yml