/
LE
lensesio
/
HashiCorp Vault API
Search skmtc…
⌘K
Docs
Sign in
Sign in
APIs
Generators
Stacks
Projects
Docs
History
Schema
Sources
Checked 45m ago · Updated 3w ago
View markdown
lensesio
HashiCorp Vault API
post
Add a new or update an existing policy.
v1
latest
OpenAPI 3.0.2
Mozilla Public License 2.0
2026-07-17
307
105
155.2 KB
auth
21
identity
105
secrets
15
system
166
get
List the enabled audit devices.
post
The hash of the given string via the given audit backend
post
Enable a new audit device at the supplied path.
delete
Disable the audit device at the given path.
get
List the currently enabled credential backends.
get
Read the configuration of the auth engine at the given path.
post
Enables a new auth method.
delete
Disable the auth method at the given auth path
get
Reads the given auth path's configuration.
post
Tune configuration parameters for a given auth path.
post
Fetches the capabilities of the given token on the given path.
post
Fetches the capabilities of the token associated with the given token, on the given path.
post
Fetches the capabilities of the given token on the given path.
get
List the request headers that are configured to be audited.
get
List the information for the given request header.
post
Enable auditing of a header.
delete
Disable auditing of the given request header.
get
Return the current CORS settings.
post
Configure the CORS settings.
delete
Remove any CORS settings.
post
Reload the given subsystem
get
Return a sanitized version of the Vault server configuration.
get
Return a list of configured UI headers.
get
Return the given UI header's configuration
post
Configure the values to be returned for the UI header.
delete
Remove a UI header.
get
Read the configuration and progress of the current root generation attempt.
post
Initializes a new root generation attempt.
delete
Cancels any in-progress root generation attempt.
get
Read the configuration and progress of the current root generation attempt.
post
Initializes a new root generation attempt.
delete
Cancels any in-progress root generation attempt.
post
Enter a single unseal key share to progress the root generation attempt.
get
Check the HA status of a Vault cluster
get
Returns the health status of Vault.
get
Information about the host instance that this Vault server is running on.
get
reports in-flight requests
get
Returns the initialization status of Vault.
post
Initialize a new Vault.
get
Report the client count metrics, for this namespace and all child namespaces.
get
Report the client count metrics, for this namespace and all child namespaces.
get
Report the number of clients for this month, for this namespace and all child namespaces.
get
Read the client count tracking configuration.
post
Enable or disable collection of client count, set retention period, or set default reporting period.
get
Backwards compatibility is not guaranteed for this API
get
Backwards compatibility is not guaranteed for this API
get
Backwards compatibility is not guaranteed for this API
get
Generate an OpenAPI 3 document of all mounted paths.
get
Lists enabled feature flags.
get
Lists all enabled and visible auth and secrets mounts.
get
Return information about the given mount.
get
Backwards compatibility is not guaranteed for this API
get
Backwards compatibility is not guaranteed for this API
get
Provides information about the backend encryption key.
get
Returns the high availability status and current leader instance of Vault.
get
List leases associated with this Vault cluster
get
Count of leases associated with this Vault cluster
post
Retrieve lease metadata.
get
Returns a list of lease ids.
get
Returns a list of lease ids.
post
Renews a lease, requesting to extend the lease.
post
Renews a lease, requesting to extend the lease.
post
Revokes a lease immediately.
post
Revokes all secrets or tokens generated under a given prefix immediately
post
Revokes all secrets (via a lease ID prefix) or tokens (via the tokens' path property) generated under a given prefix immediately.
post
Revokes a lease immediately.
post
This endpoint performs cleanup tasks that can be run if certain error conditions have occurred.
get
Read the log level for all existing loggers.
post
Modify the log level for all existing loggers.
delete
Revert the all loggers to use log level provided in config.
get
Read the log level for a single logger.
post
Modify the log level of a single logger.
delete
Revert a single logger to use log level provided in config.
get
Export the metrics aggregated for telemetry purpose.
post
Validates the login for the given MFA methods. Upon successful validation, it returns an auth response containing the client token
get
/sys/monitor
get
List the currently mounted backends.
get
Read the configuration of the secret engine at the given path.
post
Enable a new secrets engine at the given path.
delete
Disable the mount point specified at the given path.
get
Tune backend configuration parameters for this mount.
post
Tune backend configuration parameters for this mount.
get
Lists all the plugins known to Vault
get
Return the configuration data for the plugin with the given name.
post
Register a new plugin, or updates an existing one with the supplied name.
delete
Remove the plugin with the given name.
get
List the plugins in the catalog.
get
Return the configuration data for the plugin with the given name.
post
Register a new plugin, or updates an existing one with the supplied name.
delete
Remove the plugin with the given name.
post
Reload mounted plugin backends.
get
List the configured access control policies.
get
Retrieve information about the named ACL policy.
post
Add a new or update an existing ACL policy.
delete
Delete the ACL policy with the given name.
get
List the existing password policies.
get
Retrieve an existing password policy.
post
Add a new or update an existing password policy.
delete
Delete a password policy.
get
Generate a password from an existing password policy.
get
List the configured access control policies.
get
Retrieve the policy body for the named policy.
post
Add a new or update an existing policy.
delete
Delete the policy with the given name.
get
Returns an HTML page listing the available profiles.
get
Returns a sampling of all past memory allocations.
get
Returns stack traces that led to blocking on synchronization primitives
get
Returns the running program's command line.
get
Returns stack traces of all current goroutines.
get
Returns a sampling of memory allocations of live object.
get
Returns stack traces of holders of contended mutexes
get
Returns a pprof-formatted cpu profile payload.
get
Returns the program counters listed in the request.
get
Returns stack traces that led to the creation of new OS threads
get
Returns the execution trace in binary form.
get
/sys/quotas/config
post
/sys/quotas/config
get
/sys/quotas/rate-limit
get
/sys/quotas/rate-limit/{name}
post
/sys/quotas/rate-limit/{name}
delete
/sys/quotas/rate-limit/{name}
get
Read the value of the key at the given path.
post
Update the value of the key at the given path.
delete
Delete the key with given path.
get
Read the value of the key at the given path.
post
Update the value of the key at the given path.
delete
Delete the key with given path.
get
Return the backup copy of PGP-encrypted unseal keys.
delete
Delete the backup copy of PGP-encrypted unseal keys.
get
Reads the configuration and progress of the current rekey attempt.
post
Initializes a new rekey attempt.
delete
Cancels any in-progress rekey.
get
Allows fetching or deleting the backup of the rotated unseal keys.
delete
Allows fetching or deleting the backup of the rotated unseal keys.
post
Enter a single unseal key share to progress the rekey of the Vault.
get
Read the configuration and progress of the current rekey verification attempt.
post
Enter a single new key share to progress the rekey verification operation.
delete
Cancel any in-progress rekey verification operation.
post
Initiate a mount migration
get
Check status of a mount migration
post
Renews a lease, requesting to extend the lease.
post
Renews a lease, requesting to extend the lease.
get
/sys/replication/status
post
Revokes a lease immediately.
post
Revokes all secrets or tokens generated under a given prefix immediately
post
Revokes all secrets (via a lease ID prefix) or tokens (via the tokens' path property) generated under a given prefix immediately.
post
Revokes a lease immediately.
post
Rotates the backend encryption key used to persist data.
get
/sys/rotate/config
post
/sys/rotate/config
post
Seal the Vault.
get
Check the seal status of a Vault.
post
Cause the node to give up active status.
post
Generate a hash sum for input data
post
Generate a hash sum for input data
post
Generate random bytes
post
Generate random bytes
post
Generate random bytes
post
Generate random bytes
post
Unseal the Vault.
get
Returns map of historical version change entries
get
Look up wrapping properties for the requester's token.
post
Look up wrapping properties for the given token.
post
Rotates a response-wrapped token.
post
Unwraps a response-wrapped token.
post
Response-wraps an arbitrary JSON object.
system
Add a new or update an existing policy.
post
/sys/policy/{name}
Request body
SystemPolicyRequest
required
policy
string
The rules of the policy.
rules
string
The rules of the policy.
Response
OK