Skip to main content
GET
Get a vault's public key for browser-encrypted credential values

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id_or_name
string
required

Response

Vault encryption key

Public key for encrypted_value on credential fields. Use this only if you run your own credential collection web app and want values encrypted in the browser, sent to your backend still encrypted, and forwarded to Kernel's API still encrypted. In every other case, including server-side code that already holds the plaintext, use value. Each vault has its own key; a value encrypted for one vault is rejected by every other vault. The key is created on first request and stays the same for the vault's lifetime, so it may be cached.

alg
enum<string>
required

JWE key management algorithm.

Available options:
ECDH-ES
enc
enum<string>
required

JWE content encryption algorithm.

Available options:
A256GCM
jwk
object
required

P-256 public key in JWK form.

kid
string
required

Key ID. Set it as the kid protected header of every encrypted_value.