---
title: "POST /api/v1/app-connections/hashicorp-vault"
method: POST
path: "/api/v1/app-connections/hashicorp-vault"
tags: ["App Connections"]
---

# POST /api/v1/app-connections/hashicorp-vault

`POST /api/v1/app-connections/hashicorp-vault`

Create a Hashicorp Vault Connection.

## Request body

- union
  - object
    - `method` 'access-token', required — The method used to authenticate with Hashicorp Vault.
    - `credentials` object, required — The credentials used to connect with Hashicorp Vault.
      - `instanceUrl` string, uri, required — The Hashicrop Vault instance URL to connect with.
      - `namespace` string — The Hashicrop Vault namespace to connect with.
      - `accessToken` string, required — The access token used to connect with Hashicorp Vault.
    - `name` string, required — The name of the Hashicorp Vault Connection to create. Must be slug-friendly.
    - `description` string, nullable — An optional description for the Hashicorp Vault Connection.
    - `projectId` string — The ID of the project to create the Hashicorp Vault Connection in.
    - `isPlatformManagedCredentials` false — Not supported for Hashicorp Vault Connections.
    - `gatewayId` string, uuid, nullable — The Gateway ID to use for this connection.
    - `gatewayPoolId` string, uuid, nullable — The Gateway Pool ID to use for this connection.
    - `isAutoRotationEnabled` false — Not supported for Hashicorp Vault Connections.
    - `rotation` 'null', nullable — Not supported for Hashicorp Vault Connections.
  - object
    - `method` 'app-role', required — The method used to authenticate with Hashicorp Vault.
    - `credentials` object, required — The credentials used to connect with Hashicorp Vault.
      - `instanceUrl` string, uri, required — The Hashicrop Vault instance URL to connect with.
      - `namespace` string — The Hashicrop Vault namespace to connect with.
      - `roleId` string, required — The Role ID used to connect with Hashicorp Vault.
      - `secretId` string, required — The Secret ID used to connect with Hashicorp Vault.
    - `name` string, required — The name of the Hashicorp Vault Connection to create. Must be slug-friendly.
    - `description` string, nullable — An optional description for the Hashicorp Vault Connection.
    - `projectId` string — The ID of the project to create the Hashicorp Vault Connection in.
    - `isPlatformManagedCredentials` false — Not supported for Hashicorp Vault Connections.
    - `gatewayId` string, uuid, nullable — The Gateway ID to use for this connection.
    - `gatewayPoolId` string, uuid, nullable — The Gateway Pool ID to use for this connection.
    - `isAutoRotationEnabled` false — Not supported for Hashicorp Vault Connections.
    - `rotation` 'null', nullable — Not supported for Hashicorp Vault Connections.

## Response `200`

Default Response

- object
  - `appConnection` union, required
    - object
      - `id` string, uuid, required
      - `name` string, required
      - `description` string, nullable
      - `version` number
      - `orgId` string, uuid, required
      - `createdAt` string, date-time, required
      - `updatedAt` string, date-time, required
      - `isPlatformManagedCredentials` boolean, nullable
      - `gatewayId` string, uuid, nullable
      - `projectId` string, nullable
      - `isAutoRotationEnabled` boolean
      - `gatewayPoolId` string, uuid, nullable
      - `rotation` object — The credential rotation configuration, if configured.
        - `lastRotationMessage` string, nullable — The message from the last rotation attempt.
        - `rotationInterval` number, required — The interval in days between credential rotations.
        - `nextRotationAt` string, date-time, nullable — The next scheduled rotation time.
        - `rotationStatus` 'success' | 'failed', required — The status of the last rotation attempt.
        - `rotateAtUtc` object, required — The UTC time of day at which rotation should occur.
          - `hours` number, required — The hour (0-23) at which to rotate.
          - `minutes` number, required — The minute (0-59) at which to rotate.
      - `credentialsHash` string
      - `project` object, nullable
        - `name` string, required
        - `id` string, required
        - `type` string, required
        - `slug` string, required
      - `app` 'hashicorp-vault', required
      - `method` 'access-token', required
      - `credentials` object, required
        - `namespace` string — The Hashicrop Vault namespace to connect with.
        - `instanceUrl` string, uri, required — The Hashicrop Vault instance URL to connect with.
    - object
      - `id` string, uuid, required
      - `name` string, required
      - `description` string, nullable
      - `version` number
      - `orgId` string, uuid, required
      - `createdAt` string, date-time, required
      - `updatedAt` string, date-time, required
      - `isPlatformManagedCredentials` boolean, nullable
      - `gatewayId` string, uuid, nullable
      - `projectId` string, nullable
      - `isAutoRotationEnabled` boolean
      - `gatewayPoolId` string, uuid, nullable
      - `rotation` object — The credential rotation configuration, if configured.
        - `lastRotationMessage` string, nullable — The message from the last rotation attempt.
        - `rotationInterval` number, required — The interval in days between credential rotations.
        - `nextRotationAt` string, date-time, nullable — The next scheduled rotation time.
        - `rotationStatus` 'success' | 'failed', required — The status of the last rotation attempt.
        - `rotateAtUtc` object, required — The UTC time of day at which rotation should occur.
          - `hours` number, required — The hour (0-23) at which to rotate.
          - `minutes` number, required — The minute (0-59) at which to rotate.
      - `credentialsHash` string
      - `project` object, nullable
        - `name` string, required
        - `id` string, required
        - `type` string, required
        - `slug` string, required
      - `app` 'hashicorp-vault', required
      - `method` 'app-role', required
      - `credentials` object, required
        - `namespace` string — The Hashicrop Vault namespace to connect with.
        - `instanceUrl` string, uri, required — The Hashicrop Vault instance URL to connect with.
        - `roleId` string, required — The Role ID used to connect with Hashicorp Vault.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

---

[API](https://skmtc.net/infisical/apis/infisical-api.md) · [All operations](https://skmtc.net/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/infisical/infisical-api/versions/885aef3e6c11/schema)
