v1

latestOpenAPI 3.0.2Mozilla Public License 2.02026-07-17307105155.2 KB
system

Initialize a new Vault.

The Vault must not have been previously initialized. The recovery options, as well as the stored shares option, are only available when using Vault HSM.

post/sys/init

Request body

pgp_keysstring[]

Specifies an array of PGP public keys used to encrypt the output unseal keys. Ordering is preserved. The keys must be base64-encoded from their original binary representation. The size of this array must be the same as secret_shares.

recovery_pgp_keysstring[]

Specifies an array of PGP public keys used to encrypt the output recovery keys. Ordering is preserved. The keys must be base64-encoded from their original binary representation. The size of this array must be the same as recovery_shares.

recovery_sharesinteger

Specifies the number of shares to split the recovery key into.

recovery_thresholdinteger

Specifies the number of shares required to reconstruct the recovery key. This must be less than or equal to recovery_shares.

root_token_pgp_keystring

Specifies a PGP public key used to encrypt the initial root token. The key must be base64-encoded from its original binary representation.

secret_sharesinteger

Specifies the number of shares to split the unseal key into.

secret_thresholdinteger

Specifies the number of shares required to reconstruct the unseal key. This must be less than or equal secret_shares. If using Vault HSM with auto-unsealing, this value must be the same as secret_shares.

stored_sharesinteger

Specifies the number of shares that should be encrypted by the HSM and stored for auto-unsealing. Currently must be the same as secret_shares.

Response

OK