Skip to main content
A request asks someone to fill in a secret. There are two ways to send one.

Which option do you need?

Most teams need the hosted link. No code is required. Open Logins, then Requests, and click Ask someone for a login. Pick a template, and the platform gives you a link to vault.asteroid.ai. Send that link to the person however you like. They fill in the form on Asteroid’s page. The secret appears in your organization when they submit. You can also create the same link from the API. POST /agents/v2/secret-requests returns a token. The hosted page is https://vault.asteroid.ai/vault-request#<token>. Send that URL to the recipient. Use the embedded form below only when you must hide Asteroid. The rest of this page shows how to render the request on your own page, with your own components and branding. The recipient never sees vault.asteroid.ai. Pick this when you white-label the flow or keep the form inside your own product. Both options share the same request, the same token, the same seven-day expiry and the same security model. The recipient submits straight to Asteroid. The values never pass through your servers.

How the embedded form works

Your backend creates the request with your API key. Your page reads the form shape and submits the values to Asteroid.
Start from the example app. It is a small Next.js app that implements every step on this page. Copy it into your own codebase.

The contract

The public_v2 calls accept requests from any origin. They carry no session and send no cookies. The share token is the only credential.
Never send your API key to the browser. Only your backend calls the v2 endpoints.

1. Create the request

Design the form as a template in the platform: open Logins, then Secrets, then Templates. Copy its ID. Then create one request for each person you collect from:
Get the organization ID from GET /context. The response holds the request and a token:
The API returns the token once. Asteroid stores only its hash. Store the token server-side, next to your user, until the request completes. Hand it to your page when that user opens the form. name becomes the secret’s name. Omit itemKey and the server derives the key from that name. Send itemKey when you want a specific UPPER_SNAKE key. Many secrets may share a key. A later rename leaves the key unchanged. A profile cannot attach two secrets with the same key. To skip the template, send kind, fields and optional steps inline instead of templateId.

2. Read the form

Render fields in array order. When steps is not empty, show one step per page. Each step lists its fields by key. instructions is Markdown. A step can have instructions and no fields. Map each field type to an input: Write-only values never come back out of the API. Asteroid decrypts them only when a workflow uses them.

3. Submit the values

Send one entry per filled field. Leave out empty optional fields. An unknown key or a missing required value returns 400. Clean the values first, the way the hosted page does:
  • TOTP seed: accept a Base32 key or an otpauth://totp/ link. Send the Base32 secret only, uppercase, with spaces, dashes and = padding removed.
  • Card number and CVV: remove spaces and dashes.
  • URL: add https:// when the scheme is missing.
  • Readable fields: trim whitespace. Send secrets exactly as typed.
A 200 with "status": "completed" means the secret exists. Attach it to a login profile to use it in workflows. In the platform, click Add to a profile on the completed request in Logins, Requests.

Responses

Limits

Create a request when a user needs one, not on every page load. Reuse the stored token until the request completes or returns 410. Revoke unused requests with POST /secret-requests/{requestId}/revoke. The Requests tab on the Logins page creates the same request and gives you a link to vault.asteroid.ai. Send that link when you do not need the form inside your own app.