Skip to main content
POST
Create Secret Request

Authorizations

X-Api-Key
string
header
required

Body

application/json
name
string
required

Name of the secret the request creates.

Required string length: 1 - 200
title
string
required

Title shown to the recipient of the secret request.

Required string length: 1 - 200
description
string

Explanation shown to the recipient of the secret request.

Maximum string length: 2000
fields
object[]

Inline field blueprint. Required when templateId is omitted.

itemKey
string

Optional UPPER_SNAKE key. Derived from name when omitted.

Required string length: 1 - 64
Pattern: ^[A-Z0-9]+(?:_[A-Z0-9]+)*$
kind
enum<string>

Required when templateId is omitted.

Available options:
login,
api_key,
card,
custom
organizationId
string<uuid>

The organization. Defaults to the one organization the caller acts in, such as an API key's. Required when the caller belongs to several.

steps
object[]

Inline step layout. Only valid with kind and fields; rejected with templateId.

Maximum array length: 20
templateId
string<uuid>

Org template to snapshot. Mutually exclusive with kind and fields.

Response

The request has succeeded and a new resource has been created as a result.

Create response. token is the raw link secret and is returned once; the server stores only its hash.

A credential request. The recipient opens the link with no session, fills in the values, and one submit creates the vault item. The field blueprint is frozen at create.

token
string
required

Raw token for the recipient URL. Returned once.