Which option do you need?
Most teams need the hosted link. No code is required. Open Logins, then Requests, and click Ask someone for a login. Pick a template, and the platform gives you a link tovault.asteroid.ai. Send that link to the person however you like. They fill in the form on
Asteroid’s page. The secret appears in your organization when they submit.
You can also create the same link from the API. POST /agents/v2/secret-requests returns a token.
The hosted page is https://vault.asteroid.ai/vault-request#<token>. Send that URL to the recipient.
Use the embedded form below only when you must hide Asteroid. The rest of this page shows how
to render the request on your own page, with your own components and branding. The recipient never
sees vault.asteroid.ai. Pick this when you white-label the flow or keep the form inside your own
product.
Both options share the same request, the same token, the same seven-day expiry and the same
security model. The recipient submits straight to Asteroid. The values never pass through your
servers.
How the embedded form works
Your backend creates the request with your API key. Your page reads the form shape and submits the values to Asteroid.The contract
The
public_v2 calls accept requests from any origin. They carry no session and send no cookies.
The share token is the only credential.
1. Create the request
Design the form as a template in the platform: open Logins, then Secrets, then Templates. Copy its ID. Then create one request for each person you collect from:GET /context. The response holds the request and a token:
name becomes the secret’s name. Omit itemKey and the server derives the key from that
name. Send itemKey when you want a specific UPPER_SNAKE key. Many secrets may share a key. A later
rename leaves the key unchanged. A profile cannot attach two secrets with the same key.
To skip the template, send kind, fields and optional steps inline instead of templateId.
2. Read the form
fields in array order. When steps is not empty, show one step per page. Each step lists
its fields by key. instructions is Markdown. A step can have instructions and no fields.
Map each field type to an input:
Write-only values never come back out of the API. Asteroid decrypts them only when a workflow uses
them.
3. Submit the values
400.
Clean the values first, the way the hosted page does:
- TOTP seed: accept a Base32 key or an
otpauth://totp/link. Send the Base32 secret only, uppercase, with spaces, dashes and=padding removed. - Card number and CVV: remove spaces and dashes.
- URL: add
https://when the scheme is missing. - Readable fields: trim whitespace. Send secrets exactly as typed.
200 with "status": "completed" means the secret exists. Attach it to a
login profile to use it in workflows. In the platform, click Add to a profile
on the completed request in Logins, Requests.
Responses
Limits
Create a request when a user needs one, not on every page load. Reuse the stored token until the
request completes or returns
410. Revoke unused requests with
POST /secret-requests/{requestId}/revoke.
Or send the hosted link
The Requests tab on the Logins page creates the same request and gives you a link tovault.asteroid.ai. Send that link when you do not need the form inside your own app.
