v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/create-rotated-secret

Request body

ProviderTypestring
api-idstring

API ID to rotate (relevant only for rotator-type=api-key)

api-keystring

API key to rotate (relevant only for rotator-type=api-key)

application-idstring

ApplicationId (used in azure)

authentication-credentialsstring

The credentials to connect with use-user-creds/use-target-creds

auto-rotatestring

Whether to automatically rotate every --rotation-interval days, or disable existing automatic rotation [true/false]

aws-regionstring

Aws Region (relevant only for aws)

custom-payloadstring

Secret payload to be sent with rotation request (relevant only for rotator-type=custom)

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Description of the object

gcp-keystring

Base64-encoded service account private key text

gcp-service-account-emailstring

The email of the gcp service account to rotate

gcp-service-account-key-idstring

The key id of the gcp service account to rotate

grace-rotationstring

Create a new access key without deleting the old key from AWS for backup (relevant only for AWS) [true/false]

host-providerstring

Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret

jsonboolean

Set output format to JSON

keystring

The name of a key that used to encrypt the secret value (if empty, the account default protectionKey key will be used)

lock-during-sra-sessionstring

Lock this secret for read/update while an SRA session is active

metadatastring

Deprecated - use description

namestring required

Secret name

password-lengthstring

The length of the password to be generated

rotate-after-disconnectstring

StringOrBool accepts JSON strings, booleans, and numbers for backward compatibility with older SDK versions that send boolean values for rotate-after-disconnect.

rotated-passwordstring

rotated-username password (relevant only for rotator-type=password)

rotated-usernamestring

username to be rotated, if selected use-self-creds at rotator-creds-type, this username will try to rotate it's own password, if use-target-creds is selected, target credentials will be use to rotate the rotated-password (relevant only for rotator-type=password)

rotation-hourinteger

The Hour of the rotation in UTC. Default rotation-hour is 14:00

rotation-intervalstring

The number of days to wait between every automatic key rotation (1-365)

rotator-creds-typestring
rotator-custom-cmdstring

Custom rotation command (relevant only for ssh target)

rotator-typestring required

Rotator Type

same-passwordstring

Rotate same password for each host from the Linked Target (relevant only for Linked Target)

secure-access-allow-external-userboolean

Allow providing external user for a domain users (relevant only for rdp)

secure-access-aws-account-idstring

The AWS account id (relevant only for aws)

secure-access-aws-native-cliboolean

The AWS native cli

secure-access-bastion-issuerstring

Deprecated. use secure-access-certificate-issuer

secure-access-certificate-issuerstring

Path to the SSH Certificate Issuer for your Akeyless Secure Access

secure-access-db-namestring

The DB name (relevant only for DB Dynamic-Secret)

secure-access-db-schemastring

The db schema (relevant only for mssql or postgresql)

secure-access-disable-concurrent-connectionsboolean

Enable this flag to prevent simultaneous use of the same secret

secure-access-enablestring

Enable/Disable secure remote access [true/false]

secure-access-hoststring[]

Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)

secure-access-rdp-domainstring

Required when the Dynamic Secret is used for a domain user (relevant only for RDP Dynamic-Secret)

secure-access-rdp-userstring

Override the RDP Domain username (relevant only for rdp)

secure-access-urlstring

Destination URL to inject secrets

secure-access-webboolean

Enable Web Secure Remote Access

secure-access-web-browsingboolean

Secure browser viaAkeyless's Secure Remote Access (SRA) (relevant only for aws or azure)

secure-access-web-proxyboolean

Web-Proxy via Akeyless's Secure Remote Access (SRA) (relevant only for aws or azure)

ssh-passwordstring

Deprecated: use RotatedPassword

ssh-usernamestring

Deprecated: use RotatedUser

storage-account-key-namestring

The name of the storage account key to rotate [key1/key2/kerb1/kerb2] (relevat to azure-storage-account)

tagsstring[]

Add tags attached to this object

targetstring[]

A list of linked targets to be associated, Relevant only for Secure Remote Access for ssh cert issuer, ldap rotated secret and ldap dynamic secret, To specify multiple targets use argument multiple times

target-namestring required

Target name

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

user-attributestring

LDAP User Attribute, Default value "cn"

user-dnstring

LDAP User Base DN

Response

createRotatedSecretResponse wraps response body.

namestring