Orkestia
Blog
Vault

API access

Let workflows and agents call an API with a Vault secret they never receive. The Vault calls only the hosts you allowed and removes the secret from the response

TL;DR

  • Instead of asking for a secret, a workflow or agent asks the Vault to make the API call with it: vault.http.request.
  • The caller gets the response, with the secret removed. It never sees the value.
  • It works only for secrets an owner or admin has given API access: which hosts, which methods, and how the secret is sent.

1. Turn on API access for a secret

In the Console: Vault → Secrets, open the secret's Manage menu and choose API access…. Fill in the allowed hosts, the methods and how to send the secret, then use Test call to check it.

From the API, an owner or admin calls vault.secret.usage.set:

{
  "path": "github/ci/token",
  "usage": {
    "allowed_hosts": ["api.github.com"],
    "methods": ["GET", "POST"],
    "placement": { "kind": "header", "name": "Authorization", "template": "Bearer {value}" }
  }
}
FieldMeaning
allowed_hostsUp to 20 hostnames, such as api.stripe.com. List each host exactly; add :port if it is not 443
methodsAny of GET, HEAD, POST, PUT, PATCH, DELETE. Default GET
placementHow the secret is sent (below)
placement.kindSends the secret as
headerA header, such as Authorization with Bearer {value}
basicBasic auth, with the username you give and the secret as the password
queryA query parameter, such as api_key

Set usage to null to turn API access off. The secret itself is kept.

2. Give the caller use

The member or Staff agent needs the use permission on the secret. Add a policy. use does not let them read the value.

3. Make the call

Start vault.http.request:

InputMeaning
pathThe secret to use
methodOne of the allowed methods
urlAn https URL on an allowed host
headersOptional extra headers
bodyOptional request body, up to 256 KiB
timeout_secondsDefault 15, at most 30

You get back response_status_code, the main response_headers, and response_body (up to 1 MiB) with any copy of the secret replaced by [REDACTED]. If the API echoes the secret back in another form, the body is withheld and body_withheld is true.

When a call is refused

  • The secret has no API access, or the host or method is not allowed.
  • The URL is not https, or points to a private or internal address.
  • The secret is shorter than 8 characters.
  • Too many calls are running for your organization at once. Try again shortly.

Every call, allowed or refused, is recorded in the audit log.

In workflows and agents

vault.http.request can be a step in a composed workflow, and Staff agents can start it like any other workflow. Permissions are checked against the person or agent behind the run.