OpenBao
OpenBao is an open source, community-driven identity-based secrets and encryption management system, forked from HashiCorp Vault in 2023 and governed by the Linux Foundation as a sandbox project of the Open Source Security Foundation (OpenSSF). It stores and tightly controls access to tokens, passwords, certificates and encryption keys, and exposes every one of its capabilities — key/value secrets, dynamic database credentials, PKI issuance, transit encryption, leasing and revocation, policy and namespace administration, seal/unseal and cluster operations — through a single JSON HTTP API prefixed with /v1/. OpenBao is self-hosted software rather than a hosted service, so there is no vendor-operated base URL: the API is served by whatever instance an operator runs, and the CLI, the web UI and the official Go client all speak the same HTTP API. The machine-readable OpenAPI document is generated per instance at runtime from the mounted backends and is served at /v1/sys/internal/specs/openapi rather than published as a static file.
OpenBao publishes 1 API on the APIs.io network. Tagged areas include Secrets Management, Security, Identity and Access Management, Encryption, and Certificates.
The OpenBao catalog on APIs.io includes 1 event-driven AsyncAPI specification.
OpenBao’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, changelog, CLI, and 20 more developer resources.
Kin Score
APIs 1
Individual APIs this provider publishes, each with its own machine-readable definition.
OpenBao HTTP API
The OpenBao HTTP API gives full access to every OpenBao capability over REST-like HTTP verbs. All routes are prefixed with /v1/ and the API is versioned only at that prefix. Aut...
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Openbao Rate Limits
RATE LIMITSEvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Openbao Audit Events
ASYNCAPISecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.