v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/dynamic-secret-get

Request body

jsonboolean

Set output format to JSON

namestring required

Dynamic secret name

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

Response

dynamicSecretGetResponse wraps response body.

access_token_manager_idstring
acl_rulesstring[]
activeboolean
admin_namestring
admin_pwdstring
admin_rotation_interval_daysinteger
administrative_portstring
api_keystring
api_key_idstring
artifactory_admin_apikeystring
artifactory_admin_usernamestring
artifactory_base_urlstring
artifactory_token_audiencestring
artifactory_token_scopestring
authorization_portstring
aws_access_key_idstring
aws_access_modestring
aws_external_idstring
aws_regionstring
aws_role_arnsstring
aws_secret_access_keystring
aws_session_tagsstring
aws_session_tokenstring
aws_transitive_tag_keysstring
aws_user_console_accessboolean
aws_user_groupsstring
aws_user_policiesstring
aws_user_programmatic_accessboolean
azure_administrative_unitstring
azure_app_object_idstring
azure_client_idstring
azure_client_secretstring
azure_cloudstring
azure_fixed_user_name_sub_claim_keystring
azure_fixed_user_onlyboolean
azure_resource_group_namestring
azure_resource_namestring
azure_subscription_idstring
azure_tenant_idstring
azure_user_groups_obj_idstring
azure_user_portal_accessboolean
azure_user_programmatic_accessboolean
azure_user_roles_template_idstring
azure_usernamestring
cassandra_creation_statementsstring
chef_organizationsstring
chef_server_access_modestring
chef_server_host_namestring
chef_server_keystring
chef_server_portstring
chef_server_urlstring
chef_server_usernamestring
chef_skip_sslboolean
client_authentication_typestring
client_certificatestring

(Optional) ClientCertificate defines the client certificate for mutual TLS. Must be base64 certificate loaded by UI using file loader field

client_key_passphrasestring

(Optional) ClientKeyPassphrase defines the passphrase for the client private key

client_private_keystring

(Optional) ClientPrivateKey defines the client private key for mutual TLS. Must be base64 private key loaded by UI using file loader field

cloud_service_providerstring
cluster_modeboolean
connection_typestring
create_sync_urlstring
db_client_idstring
db_client_secretstring
db_host_namestring
db_isolation_levelstring
db_max_idle_connsstring
db_max_open_connsstring
db_namestring
db_portstring
db_private_keystring

(Optional) Private Key in PEM format

db_private_key_passphrasestring
db_pwdstring
db_server_certificatesstring

(Optional) DBServerCertificates defines the set of root certificate authorities that clients use when verifying server certificates. If DBServerCertificates is empty, TLS uses the host's root CA set.

db_server_namestring

(Optional) ServerName is used to verify the hostname on the returned certificates unless InsecureSkipVerify is given. It is also included in the client's handshake to support virtual hosting unless it is an IP address.

db_tenant_idstring
db_user_namestring
delete_protectionboolean
dynamic_secret_idinteger
dynamic_secret_keystring
dynamic_secret_namestring
dynamic_secret_typestring
eks_access_key_idstring
eks_assume_rolestring
eks_cluster_ca_certificatestring
eks_cluster_endpointstring
eks_cluster_namestring
eks_regionstring
eks_secret_access_keystring
enable_admin_rotationboolean
enable_mtlsboolean

(Optional) EnableMTLS defines if mutual TLS will be used to connect to DB

enforce_replay_preventionboolean

relevant for PRIVATE_KEY_JWT client authentication type

expiration_datestring date-time
externally_provided_userstring
failure_messagestring
fixed_user_onlystring
gcp_access_typestring
gcp_fixed_user_claim_keynamestring
gcp_key_algostring
gcp_project_idstring
gcp_role_bindingsobject
gcp_role_namesstring
gcp_service_account_emailstring

GCPServiceAccountEmail overrides the deprecated field from the target

gcp_service_account_keystring
gcp_service_account_key_base64string
gcp_service_account_key_idstring
gcp_service_account_typestring
gcp_tmp_service_account_namestring
gcp_token_lifetimestring
gcp_token_scopestring
gcp_token_typestring
github_app_idinteger
github_app_private_keystring
github_base_urlstring
github_installation_idinteger
github_installation_token_permissionsobject
github_installation_token_repositoriesstring[]
github_installation_token_repositories_idsinteger[]
github_organization_namestring
github_repository_pathstring
gitlab_access_tokenstring
gitlab_access_typestring
gitlab_certificatestring
gitlab_group_namestring
gitlab_project_namestring
gitlab_rolestring
gitlab_token_scopestring[]
gitlab_urlstring
gke_cluster_ca_certificatestring
gke_cluster_endpointstring
gke_cluster_namestring
gke_service_account_keystring
gke_service_account_namestring
google_workspace_access_modestring
google_workspace_admin_namestring
google_workspace_fixed_user_name_sub_claim_keystring
google_workspace_group_namestring
google_workspace_group_rolestring
google_workspace_role_namestring
google_workspace_role_scopestring
grace_rotated_secret_keystring
grant_typesstring[]
groupsstring
hanadb_creation_statementsstring
hanadb_revocation_statementsstring
host_namestring
host_portstring
implementation_typestring
is_fixed_userstring
issuerstring

relevant for CLIENT_TLS_CERTIFICATE client authentication type

jwksstring
jwks_urlstring
k8s_allowed_namespacesstring

comma-separated list of allowed namespaces. Can hold just * which signifies that any namespace is allowed

k8s_auth_typestring
k8s_bearer_tokenstring
k8s_client_cert_datastring

For K8s Client certificates authentication

k8s_client_key_datastring
k8s_cluster_ca_certificatestring
k8s_cluster_endpointstring
k8s_cluster_namestring
k8s_dynamic_modeboolean

when native k8s is in dynamic mode, user can define allowed namespaces, K8sServiceAccount doesn't exist from the start and will only be created at time of getting dynamic secret value By default dynamic mode is false and producer behaves like it did before

k8s_multiple_doc_yaml_temp_definitioninteger[]

Yaml definition for creation of temporary objects. Field that can hold multiple docs from which following will be extracted: ServiceAccount, Role/ClusterRole and RoleBinding/ClusterRoleBinding. If ServiceAccount not specified - it will be generated automatically

k8s_namespacestring
k8s_role_namestring

Name of the pre-existing Role or ClusterRole to bind a generated service account to.

k8s_role_typestring
k8s_service_accountstring
last_admin_rotationinteger
ldap_audiencestring
ldap_bind_dnstring
ldap_bind_passwordstring
ldap_certificatestring
ldap_fixed_user_name_sub_claim_keystring
ldap_fixed_user_typestring
ldap_group_dnstring
ldap_token_expirationstring
ldap_urlstring
ldap_user_attrstring
ldap_user_dnstring
metadatastring
mongodb_atlas_api_private_keystring
mongodb_atlas_api_public_keystring
mongodb_atlas_project_idstring

mongodb atlas fields

mongodb_custom_datastring
mongodb_db_namestring

common fields

mongodb_default_auth_dbstring
mongodb_host_portstring
mongodb_is_atlasboolean
mongodb_passwordstring
mongodb_rolesstring

common fields

mongodb_scopesstring
mongodb_uri_connectionstring

mongodb fields

mongodb_uri_optionsstring
mongodb_usernamestring
mssql_allowed_db_namesstring

Comma-separated list of allowed DB names for runtime selection when fetching the secret value. Empty string => use target DB name only (no override allowed) "*" => any DB name is allowed One or more names => user must select one of the provided names

mssql_creation_statementsstring
mssql_revocation_statementsstring
mysql_creation_statementsstring
mysql_revocation_statementsstring
openai_urlstring
oracle_creation_statementsstring
oracle_revocation_statementsstring
organization_idstring
passwordstring
password_lengthinteger
password_policystring
payloadstring
ping_urlstring
postgres_creation_statementsstring
postgres_revocation_statementsstring
privileged_userstring
project_idstring
rabbitmq_server_passwordstring
rabbitmq_server_uristring
rabbitmq_server_userstring
rabbitmq_user_conf_permissionstring
rabbitmq_user_read_permissionstring
rabbitmq_user_tagsstring
rabbitmq_user_vhoststring
rabbitmq_user_write_permissionstring
rdp_fixed_user_name_sub_claim_keystring
redirect_urisstring[]
redshift_creation_statementsstring
restricted_scopesstring[]
revoke_sync_urlstring
rotate_sync_urlstring
scopesstring[]
session_extension_warn_interval_mininteger
sf_accountstring
sf_auth_modestring
sf_key_algostring
sf_user_rolestring

generated users info

sf_warehouse_namestring
should_stopstring

TODO delete this after migration

signing_algorithmstring
ssl_connection_certificatestring

(Optional) SSLConnectionCertificate defines the certificate for SSL connection. Must be base64 certificate loaded by UI using file loader field

ssl_connection_modeboolean

(Optional) SSLConnectionMode defines if SSL mode will be used to connect to DB

subject_dnstring
tagsstring[]
timeout_secondsinteger
use_gw_cloud_identityboolean
use_gw_service_accountboolean
user_namestring
user_passwordstring
user_principal_namestring
user_ttlstring
username_lengthinteger
username_policystring
username_templatestring
venafi_allow_subdomainsboolean
venafi_allowed_domainsstring[]
venafi_api_keystring
venafi_auto_generated_folderstring
venafi_base_urlstring
venafi_root_first_in_chainboolean
venafi_sign_using_akeyless_pkiboolean
venafi_signer_key_namestring
venafi_store_private_keyboolean
venafi_tpp_access_tokenstring
venafi_tpp_client_idstring
venafi_tpp_passwordstring

Deprecated: VenafiAccessToken and VenafiRefreshToken should be used instead

venafi_tpp_refresh_tokenstring
venafi_tpp_usernamestring

Deprecated: VenafiAccessToken and VenafiRefreshToken should be used instead

venafi_use_tppboolean
venafi_zonestring
warn_before_user_expiration_mininteger