openapi: 3.0.0 info: title: Infisical API description: List of all available APIs that can be consumed version: 1.0.0 servers: - url: https://infisical.com description: Production server - url: http://localhost:8080 description: Local server paths: /api/v1/secret/{secretId}/secret-versions: get: summary: Return secret versions description: Return secret versions parameters: - name: secretId in: path required: true schema: type: string description: ID of secret - name: offset description: Number of versions to skip required: false in: query schema: type: string - name: limit description: Maximum number of versions to return required: false in: query schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: secretVersions: type: array items: $ref: '#/components/schemas/SecretVersion' description: Secret versions security: - apiKeyAuth: [] /api/v1/secret/{secretId}/secret-versions/rollback: post: summary: Roll back secret to a version. description: Roll back secret to a version. parameters: - name: secretId in: path required: true schema: type: string description: ID of secret responses: '200': description: OK content: application/json: schema: type: object properties: secret: type: object $ref: '#/components/schemas/Secret' description: Secret rolled back to security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: version: type: integer description: Version of secret to roll back to /api/v1/secret-snapshot/{secretSnapshotId}: get: description: '' parameters: - name: secretSnapshotId in: path required: true schema: type: string responses: '200': description: OK /api/v1/users/me/ip: get: description: '' responses: '200': description: OK /api/v1/workspace/{workspaceId}/secret-snapshots: get: summary: Return project secret snapshot ids description: Return project secret snapshots ids parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project - name: offset description: Number of secret snapshots to skip required: false in: query schema: type: string - name: limit description: Maximum number of secret snapshots to return required: false in: query schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: secretSnapshots: type: array items: $ref: '#/components/schemas/SecretSnapshot' description: Project secret snapshots security: - apiKeyAuth: [] /api/v1/workspace/{workspaceId}/secret-snapshots/count: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/secret-snapshots/rollback: post: summary: >- Roll back project secrets to those captured in a secret snapshot version. description: >- Roll back project secrets to those captured in a secret snapshot version. parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project responses: '200': description: OK content: application/json: schema: type: object properties: secrets: type: array items: $ref: '#/components/schemas/Secret' description: Secrets rolled back to security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: version: type: integer description: Version of secret snapshot to roll back to /api/v1/workspace/{workspaceId}/logs: get: summary: Return project (audit) logs description: Return project (audit) logs parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project - name: userId description: ID of project member required: false in: query schema: type: string - name: offset description: Number of logs to skip required: false in: query schema: type: string - name: limit description: Maximum number of logs to return required: false in: query schema: type: string - name: sortBy description: Order to sort the logs by schema: type: string enum: - oldest - recent required: false in: query - name: actionNames description: Names of log actions (comma-separated) required: false in: query schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: logs: type: array items: $ref: '#/components/schemas/Log' description: Project logs security: - apiKeyAuth: [] /api/v1/workspace/{workspaceId}/audit-logs: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/audit-logs/filters/actors: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/trusted-ips: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/workspace/{workspaceId}/trusted-ips/{trustedIpId}: patch: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: trustedIpId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request delete: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: trustedIpId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/action/{actionId}: get: description: '' parameters: - name: actionId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/plans/table: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/plan: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/session/trial: post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/plan/billing: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/plan/table: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/billing-details: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK patch: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/billing-details/payment-methods: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/billing-details/payment-methods/{pmtMethodId}: delete: description: '' parameters: - name: organizationId in: path required: true schema: type: string - name: pmtMethodId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/billing-details/tax-ids: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/billing-details/tax-ids/{taxId}: delete: description: '' parameters: - name: organizationId in: path required: true schema: type: string - name: taxId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/invoices: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organizations/{organizationId}/licenses: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/sso/redirect/google: get: description: '' parameters: - name: callback_port in: query schema: type: string responses: default: description: '' /api/v1/sso/google: get: description: '' responses: default: description: '' /api/v1/sso/redirect/github: get: description: '' parameters: - name: callback_port in: query schema: type: string responses: default: description: '' /api/v1/sso/github: get: description: '' responses: default: description: '' /api/v1/sso/redirect/saml2/{ssoIdentifier}: get: description: '' parameters: - name: ssoIdentifier in: path required: true schema: type: string - name: callback_port in: query schema: type: string responses: default: description: '' /api/v1/sso/saml2/{ssoIdentifier}: post: description: '' parameters: - name: ssoIdentifier in: path required: true schema: type: string responses: default: description: '' /api/v1/sso/config: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK '400': description: Bad Request patch: description: '' responses: '200': description: OK '400': description: Bad Request /api/v1/cloud-products/: get: description: '' responses: '200': description: OK /api/v1/signup/email/signup: post: description: '' responses: '200': description: OK '403': description: Forbidden /api/v1/signup/email/verify: post: description: '' responses: '200': description: OK '403': description: Forbidden /api/v1/auth/token: post: description: '' responses: '200': description: OK /api/v1/auth/login1: post: description: '' responses: '200': description: OK /api/v1/auth/login2: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/auth/logout: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK /api/v1/auth/checkAuth: post: description: '' responses: '200': description: OK /api/v1/auth/sessions: delete: description: '' responses: '200': description: OK /api/v1/bot/{workspaceId}: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/bot/{botId}/active: patch: description: '' parameters: - name: botId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/user/: get: description: '' responses: '200': description: OK /api/v1/user-action/: post: description: '' responses: '200': description: OK get: description: '' responses: '200': description: OK /api/v1/organization/: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK /api/v1/organization/{organizationId}: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/users: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/my-workspaces: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/name: patch: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/incidentContactOrg: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/customer-portal-session: post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/organization/{organizationId}/workspace-memberships: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/keys: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/users: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK '400': description: Bad Request /api/v1/workspace/{workspaceId}: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/name: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/invite-signup: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/integrations: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/authorizations: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/workspace/{workspaceId}/service-tokens: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/membership-org/membershipOrg/{membershipOrgId}/change-role: post: description: '' parameters: - name: membershipOrgId in: path required: true schema: type: string responses: '200': description: OK /api/v1/membership-org/{membershipOrgId}: delete: description: '' parameters: - name: membershipOrgId in: path required: true schema: type: string responses: default: description: '' /api/v1/membership/{workspaceId}/connect: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/membership/{membershipId}: delete: description: '' parameters: - name: membershipId in: path required: true schema: type: string responses: '200': description: OK /api/v1/membership/{membershipId}/change-role: post: description: '' parameters: - name: membershipId in: path required: true schema: type: string responses: '200': description: OK /api/v1/key/{workspaceId}: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/key/{workspaceId}/latest: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v1/invite-org/signup: post: description: '' parameters: - name: host in: header schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/invite-org/verify: post: description: '' responses: '200': description: OK /api/v1/secret/{workspaceId}: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secrets: example: any keys: example: any environment: example: any channel: example: any get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: query schema: type: string - name: channel in: query schema: type: string responses: '200': description: OK /api/v1/secret/{workspaceId}/service-token: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: query schema: type: string - name: channel in: query schema: type: string responses: '200': description: OK /api/v1/service-token/: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK '400': description: Bad Request requestBody: content: application/json: schema: type: object properties: name: example: any workspaceId: example: any environment: example: any expiresIn: example: any publicKey: example: any encryptedKey: example: any nonce: example: any /api/v1/password/srp1: post: description: '' responses: '200': description: OK /api/v1/password/change-password: post: description: '' responses: '200': description: OK '400': description: Bad Request /api/v1/password/email/password-reset: post: description: '' responses: '200': description: OK /api/v1/password/email/password-reset-verify: post: description: '' responses: '200': description: OK '403': description: Forbidden /api/v1/password/backup-private-key: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK '400': description: Bad Request /api/v1/password/password-reset: post: description: '' responses: '200': description: OK /api/v1/integration/: post: description: '' responses: '200': description: OK /api/v1/integration/{integrationId}: patch: description: '' parameters: - name: integrationId in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: integrationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration/manual-sync: post: description: '' responses: '200': description: OK /api/v1/integration-auth/integration-options: get: description: '' responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request delete: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/integration-auth/oauth-token: post: description: '' responses: '200': description: OK /api/v1/integration-auth/access-token: post: description: '' responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/apps: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/teams: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/vercel/branches: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/railway/environments: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/railway/services: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/bitbucket/workspaces: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/northflank/secret-groups: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/integration-auth/{integrationAuthId}/teamcity/build-configs: get: description: '' parameters: - name: integrationAuthId in: path required: true schema: type: string responses: '200': description: OK /api/v1/folders/: post: summary: Create a folder description: Create a new folder in a specified workspace and environment responses: '200': description: OK content: application/json: schema: type: object properties: folder: type: object properties: id: type: string example: someFolderId name: type: string example: my_folder description: Details of the created folder '400': description: >- Bad Request. For example, 'Folder name cannot contain spaces. Only underscore and dashes' '401': description: Unauthorized request. For example, 'Folder Permission Denied' security: - apiKeyAuth: [] requestBody: content: application/json: schema: type: object properties: workspaceId: type: string description: ID of the workspace where the folder will be created example: someWorkspaceId environment: type: string description: Environment where the folder will reside example: production folderName: type: string description: Name of the folder to be created example: my_folder parentFolderId: type: string description: >- ID of the parent folder under which this folder will be created. If not specified, it will be created at the root level. example: someParentFolderId required: - workspaceId - environment - folderName get: summary: Retrieve folders based on specific conditions description: >- Fetches folders from the specified workspace and environment, optionally providing either a parentFolderId or a parentFolderPath to narrow down results parameters: - name: workspaceId description: ID of the workspace from which the folders are to be fetched required: true in: query schema: type: string - name: environment description: Environment where the folder is located required: true in: query schema: type: string - name: parentFolderId description: ID of the parent folder required: false in: query schema: type: string - name: parentFolderPath description: Path of the parent folder, like /folder1/folder2 required: false in: query schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: folders: type: array items: type: object properties: id: type: string example: someFolderId name: type: string example: someFolderName description: List of folders dir: type: array items: type: object properties: name: type: string example: parentFolderName id: type: string example: parentFolderId description: List of directories '400': description: Bad Request. For instance, 'The folder doesn't exist' '401': description: Unauthorized request. For example, 'Folder Permission Denied' security: - apiKeyAuth: [] /api/v1/folders/{folderId}: patch: summary: Update a folder by ID description: >- Update the name of a folder in a specified workspace and environment by its ID parameters: - name: folderId in: path required: true schema: type: string description: ID of the folder to be updated responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: Successfully updated folder folder: type: object properties: name: type: string example: updated_folder_name id: type: string example: someFolderId description: Details of the updated folder '400': description: >- Bad Request. Reasons can include 'The folder doesn't exist' or 'Folder name cannot contain spaces. Only underscore and dashes' '401': description: Unauthorized request. For example, 'Folder Permission Denied' security: - apiKeyAuth: [] requestBody: content: application/json: schema: type: object properties: workspaceId: type: string description: ID of the workspace where the folder is located example: someWorkspaceId environment: type: string description: Environment where the folder is located example: production name: type: string description: New name for the folder example: updated_folder_name required: - workspaceId - environment - name delete: summary: Delete a folder by ID description: >- Delete the specified folder from a specified workspace and environment using its ID parameters: - name: folderId in: path required: true schema: type: string description: ID of the folder to be deleted responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: successfully deleted folders folders: type: array items: type: object properties: id: type: string example: someFolderId name: type: string example: someFolderName description: List of IDs and names of the deleted folders '400': description: Bad Request. Reasons can include 'The folder doesn't exist' '401': description: Unauthorized request. For example, 'Folder Permission Denied' security: - apiKeyAuth: [] requestBody: content: application/json: schema: type: object properties: workspaceId: type: string description: ID of the workspace where the folder is located example: someWorkspaceId environment: type: string description: Environment where the folder is located example: production required: - workspaceId - environment /api/v1/secret-scanning/create-installation-session/organization/{organizationId}: post: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/secret-scanning/link-installation: post: description: '' responses: '200': description: OK /api/v1/secret-scanning/installation-status/organization/{organizationId}: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/secret-scanning/organization/{organizationId}/risks: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v1/secret-scanning/organization/{organizationId}/risks/{riskId}/status: post: description: '' parameters: - name: organizationId in: path required: true schema: type: string - name: riskId in: path required: true schema: type: string responses: '200': description: OK /api/v1/webhooks/: post: description: '' responses: '200': description: OK get: description: '' responses: '200': description: OK /api/v1/webhooks/{webhookId}: patch: description: '' parameters: - name: webhookId in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: webhookId in: path required: true schema: type: string responses: '200': description: OK /api/v1/webhooks/{webhookId}/test: post: description: '' parameters: - name: webhookId in: path required: true schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v1/secret-imports/: post: summary: Create secret import description: Create a new secret import for a specified workspace and environment responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: successfully created secret import description: Confirmation of secret import creation '400': description: Bad Request. For example, 'Secret import already exist' '401': description: Unauthorized request. For example, 'Folder Permission Denied' '404': description: Resource Not Found. For example, 'Failed to find folder' requestBody: content: application/json: schema: type: object properties: workspaceId: type: string description: ID of the workspace where the secret import will be created example: someWorkspaceId environment: type: string description: Environment to import to example: production folderId: type: string description: Folder ID. Use root for the root folder. example: my_folder secretImport: type: object properties: environment: type: string description: Import from environment example: development secretPath: type: string description: Import from secret path example: /user/oauth required: - workspaceId - environment - folderName get: summary: Retrieve secret imports description: >- Fetches the secret imports based on the workspaceId, environment, and folderId parameters: - name: workspaceId in: query description: ID of the workspace of secret imports to get required: true example: workspace12345 schema: type: string - name: environment in: query description: Environment of secret imports to get required: true example: production schema: type: string - name: folderId in: query description: 'ID of the folder containing the secret imports. Default: root' required: false example: folder12345 schema: type: string responses: '200': description: Successfully retrieved secret import content: application/json: schema: type: object properties: secretImport: type: object description: Details of a secret import '401': description: Unauthorized access due to invalid token or scope '403': description: Forbidden access due to insufficient permissions /api/v1/secret-imports/{id}: put: summary: Update a secret import description: >- Updates an existing secret import based on the provided ID and new import details parameters: - name: id in: path required: true schema: type: string description: ID of the secret import to be updated example: import12345 responses: '200': description: Successfully updated the secret import content: application/json: schema: type: object properties: message: type: string example: successfully updated secret import '400': description: Bad Request - Import not found '401': description: Unauthorized access due to invalid token or scope '403': description: Forbidden access due to insufficient permissions requestBody: content: application/json: schema: type: object properties: secretImports: type: array description: List of new secret imports items: type: object properties: environment: type: string description: Environment of the secret import example: production secretPath: type: string description: Path of the secret import example: /path/to/secret required: - environment - secretPath required: - secretImports delete: summary: Delete secret import description: Delete secret import parameters: - name: id in: path required: true schema: type: string description: ID of the secret import example: 12345abcde responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: successfully delete secret import description: Confirmation of secret import deletion requestBody: content: application/json: schema: type: object properties: secretImportEnv: type: string description: Import from environment example: someWorkspaceId secretImportPath: type: string description: Import from secret path example: production required: - id - secretImportEnv - secretImportPath /api/v1/secret-imports/secrets: get: description: '' responses: '200': description: OK /api/v1/roles/: post: description: '' responses: '200': description: OK get: description: '' responses: '200': description: OK /api/v1/roles/{id}: patch: description: '' parameters: - name: id in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: id in: path required: true schema: type: string responses: '200': description: OK /api/v1/roles/organization/{orgId}/permissions: get: description: '' parameters: - name: orgId in: path required: true schema: type: string responses: '200': description: OK /api/v1/roles/workspace/{workspaceId}/permissions: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v2/signup/complete-account/signup: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK '403': description: Forbidden requestBody: content: application/json: schema: type: object properties: email: example: any firstName: example: any lastName: example: any protectedKey: example: any protectedKeyIV: example: any protectedKeyTag: example: any publicKey: example: any encryptedPrivateKey: example: any encryptedPrivateKeyIV: example: any encryptedPrivateKeyTag: example: any salt: example: any verifier: example: any organizationName: example: any /api/v2/signup/complete-account/invite: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK '403': description: Forbidden requestBody: content: application/json: schema: type: object properties: email: example: any firstName: example: any lastName: example: any protectedKey: example: any protectedKeyIV: example: any protectedKeyTag: example: any publicKey: example: any encryptedPrivateKey: example: any encryptedPrivateKeyIV: example: any encryptedPrivateKeyTag: example: any salt: example: any verifier: example: any /api/v2/auth/login1: post: description: '' responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: email: example: any clientPublicKey: example: any /api/v2/auth/login2: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK '400': description: Bad Request requestBody: content: application/json: schema: type: object properties: email: example: any clientProof: example: any /api/v2/auth/mfa/send: post: description: '' responses: '200': description: OK /api/v2/auth/mfa/verify: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK /api/v2/users/me: get: summary: Retrieve the current user on the request description: Retrieve the current user on the request responses: '200': description: OK content: application/json: schema: type: object properties: user: type: object $ref: '#/components/schemas/CurrentUser' description: Current user on request security: - apiKeyAuth: [] /api/v2/users/me/mfa: patch: description: '' responses: '200': description: OK /api/v2/users/me/name: patch: description: '' responses: '200': description: OK /api/v2/users/me/auth-methods: put: description: '' responses: '200': description: OK '400': description: Bad Request /api/v2/users/me/organizations: get: summary: Return organizations that current user is part of description: Return organizations that current user is part of responses: '200': description: OK content: application/json: schema: type: object properties: organizations: type: array items: $ref: '#/components/schemas/Organization' description: Organizations that user is part of security: - apiKeyAuth: [] /api/v2/users/me/api-keys: get: description: '' responses: '200': description: OK post: description: '' responses: '200': description: OK /api/v2/users/me/api-keys/{apiKeyDataId}: delete: description: '' parameters: - name: apiKeyDataId in: path required: true schema: type: string responses: '200': description: OK /api/v2/users/me/sessions: get: description: '' responses: '200': description: OK delete: description: '' responses: '200': description: OK /api/v2/organizations/{organizationId}/memberships: get: summary: Return organization memberships description: Return organization memberships parameters: - name: organizationId in: path required: true schema: type: string description: ID of organization responses: '200': description: OK content: application/json: schema: type: object properties: memberships: type: array items: $ref: '#/components/schemas/MembershipOrg' description: Memberships of organization security: - apiKeyAuth: [] /api/v2/organizations/{organizationId}/memberships/{membershipId}: patch: summary: Update organization membership description: Update organization membership parameters: - name: organizationId in: path required: true schema: type: string description: ID of organization - name: membershipId in: path required: true schema: type: string description: ID of organization membership to update responses: '200': description: OK content: application/json: schema: type: object properties: membership: $ref: '#/components/schemas/MembershipOrg' description: Updated organization membership security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: role: type: string description: >- Role of organization membership - either owner, admin, or member delete: summary: Delete organization membership description: Delete organization membership parameters: - name: organizationId in: path required: true schema: type: string description: ID of organization - name: membershipId in: path required: true schema: type: string description: ID of organization membership to delete responses: '200': description: OK content: application/json: schema: type: object properties: membership: $ref: '#/components/schemas/MembershipOrg' description: Deleted organization membership security: - apiKeyAuth: [] /api/v2/organizations/{organizationId}/workspaces: get: summary: Return projects in organization that user is part of description: Return projects in organization that user is part of parameters: - name: organizationId in: path required: true schema: type: string description: ID of organization responses: '200': description: OK content: application/json: schema: type: object properties: workspaces: type: array items: $ref: '#/components/schemas/Project' description: Projects of organization security: - apiKeyAuth: [] /api/v2/organizations/{organizationId}/service-accounts: get: description: '' parameters: - name: organizationId in: path required: true schema: type: string responses: '200': description: OK /api/v2/workspace/{workspaceId}/environments: post: summary: Create environment description: Create environment parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: Successfully created new environment workspace: type: string example: someWorkspaceId environment: type: object properties: name: type: string example: someEnvironmentName slug: type: string example: someEnvironmentSlug description: Response after creating a new environment '400': description: Bad Request security: - apiKeyAuth: [] requestBody: content: application/json: schema: type: object properties: environmentName: type: string description: Name of the environment example: development environmentSlug: type: string description: Slug of the environment example: dev-environment required: - environmentName - environmentSlug put: summary: Rename workspace environment description: Rename a specific environment within a workspace parameters: - name: workspaceId in: path required: true schema: type: string description: ID of the workspace responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: Successfully update environment workspace: type: string example: someWorkspaceId environment: type: object properties: name: type: string example: Staging-Renamed slug: type: string example: staging-renamed description: Details of the renamed environment requestBody: content: application/json: schema: type: object properties: environmentName: type: string description: New name for the environment example: Staging-Renamed environmentSlug: type: string description: New slug for the environment example: staging-renamed oldEnvironmentSlug: type: string description: Current slug of the environment to rename example: staging-old required: - environmentName - environmentSlug - oldEnvironmentSlug patch: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK delete: summary: Delete workspace environment description: Delete a specific environment from a workspace parameters: - name: workspaceId in: path required: true schema: type: string description: ID of the workspace responses: '200': description: OK content: application/json: schema: type: object properties: message: type: string example: Successfully deleted environment workspace: type: string example: someWorkspaceId environment: type: string example: dev-environment description: Response after deleting an environment from a workspace security: - apiKeyAuth: [] requestBody: content: application/json: schema: type: object properties: environmentSlug: type: string description: Slug of the environment to delete example: dev-environment required: - environmentSlug get: summary: Get all accessible environments of a workspace description: >- Fetch all environments that the user has access to in a specified workspace parameters: - name: workspaceId in: path required: true schema: type: string description: ID of the workspace responses: '200': description: OK content: application/json: schema: type: object properties: accessibleEnvironments: type: array items: type: object properties: name: type: string example: Development slug: type: string example: development isWriteDenied: type: boolean example: false isReadDenied: type: boolean example: false description: >- List of environments the user has access to in the specified workspace security: - apiKeyAuth: [] /api/v2/workspace/{workspaceId}/tags: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v2/workspace/tags/{tagId}: delete: description: '' parameters: - name: tagId in: path required: true schema: type: string responses: '200': description: OK /api/v2/workspace/{workspaceId}/secrets: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secrets: example: any keys: example: any environment: example: any channel: example: any get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: query schema: type: string - name: channel in: query schema: type: string responses: '200': description: OK /api/v2/workspace/{workspaceId}/encrypted-key: get: summary: Return encrypted project key description: Return encrypted project key parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/ProjectKey' description: Encrypted project key for the given project security: - apiKeyAuth: [] /api/v2/workspace/{workspaceId}/service-token-data: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v2/workspace/{workspaceId}/memberships: get: summary: Return project memberships description: Return project memberships parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project responses: '200': description: OK content: application/json: schema: type: object properties: memberships: type: array items: $ref: '#/components/schemas/Membership' description: Memberships of project security: - apiKeyAuth: [] /api/v2/workspace/{workspaceId}/memberships/{membershipId}: patch: summary: Update project membership description: Update project membership parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project - name: membershipId in: path required: true schema: type: string description: ID of project membership to update responses: '200': description: OK content: application/json: schema: type: object properties: membership: $ref: '#/components/schemas/Membership' description: Updated membership security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: role: type: string description: Role of membership - either admin or member delete: summary: Delete project membership description: Delete project membership parameters: - name: workspaceId in: path required: true schema: type: string description: ID of project - name: membershipId in: path required: true schema: type: string description: ID of project membership to delete responses: '200': description: OK content: application/json: schema: type: object properties: membership: $ref: '#/components/schemas/Membership' description: Deleted membership security: - apiKeyAuth: [] /api/v2/workspace/{workspaceId}/auto-capitalization: patch: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v2/secret/batch-create/workspace/{workspaceId}/environment/{environment}: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secrets: example: any /api/v2/secret/workspace/{workspaceId}/environment/{environment}: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secret: example: any /api/v2/secret/workspace/{workspaceId}: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environment in: query schema: type: string responses: '200': description: OK /api/v2/secret/{secretId}: get: description: '' parameters: - name: secretId in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: secretId in: path required: true schema: type: string responses: '200': description: OK /api/v2/secret/batch/workspace/{workspaceId}/environment/{environmentName}: delete: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environmentName in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secretIds: example: any /api/v2/secret/batch-modify/workspace/{workspaceId}/environment/{environmentName}: patch: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environmentName in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secrets: example: any /api/v2/secret/workspace/{workspaceId}/environment/{environmentName}: patch: description: '' parameters: - name: workspaceId in: path required: true schema: type: string - name: environmentName in: path required: true schema: type: string responses: '200': description: OK requestBody: content: application/json: schema: type: object properties: secret: example: any /api/v2/secrets/batch: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK /api/v2/secrets/: post: summary: Create new secret(s) description: Create one or many secrets for a given project and environment. parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: secrets: type: array items: $ref: '#/components/schemas/Secret' description: >- Newly-created secrets for the given project and environment security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: workspaceId: type: string description: ID of project environment: type: string description: Environment within project secrets: $ref: '#/components/schemas/CreateSecret' description: Secret(s) to create - object or array of objects get: summary: Read secrets description: Read secrets from a project and environment parameters: - name: workspaceId description: ID of project required: true in: query schema: type: string - name: environment description: Environment within project required: true in: query schema: type: string - name: user-agent in: header schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: secrets: type: array items: $ref: '#/components/schemas/Secret' description: Secrets for the given project and environment security: - apiKeyAuth: [] patch: summary: Update secret(s) description: Update secret(s) responses: '200': description: OK content: application/json: schema: type: object properties: secrets: type: array items: $ref: '#/components/schemas/Secret' description: Updated secrets security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: secrets: $ref: '#/components/schemas/UpdateSecret' description: Secret(s) to update - object or array of objects delete: summary: Delete secret(s) description: Delete one or many secrets by their ID(s) parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK content: application/json: schema: type: object properties: secrets: type: array items: $ref: '#/components/schemas/Secret' description: Deleted secrets security: - apiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object properties: secretIds: type: string description: ID(s) of secrets - string or array of strings /api/v2/service-token/: get: summary: Return Infisical Token data description: Return Infisical Token data responses: '200': description: OK content: application/json: schema: type: object properties: serviceTokenData: type: object $ref: '#/components/schemas/ServiceTokenData' description: Details of service token security: - bearerAuth: [] post: description: '' responses: '200': description: OK /api/v2/service-token/{serviceTokenDataId}: delete: description: '' parameters: - name: serviceTokenDataId in: path required: true schema: type: string responses: '200': description: OK /api/v3/auth/login1: post: description: '' responses: '200': description: OK /api/v3/auth/login2: post: description: '' parameters: - name: user-agent in: header schema: type: string responses: '200': description: OK '400': description: Bad Request /api/v3/secrets/raw: get: description: '' responses: '200': description: OK /api/v3/secrets/raw/{secretName}: get: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK post: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK patch: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK /api/v3/secrets/: get: description: '' responses: '200': description: OK /api/v3/secrets/{secretName}: post: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK get: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK patch: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK delete: description: '' parameters: - name: secretName in: path required: true schema: type: string responses: '200': description: OK /api/v3/workspaces/{workspaceId}/secrets/blind-index-status: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v3/workspaces/{workspaceId}/secrets: get: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v3/workspaces/{workspaceId}/secrets/names: post: description: '' parameters: - name: workspaceId in: path required: true schema: type: string responses: '200': description: OK /api/v3/signup/complete-account/signup: post: description: '' parameters: - name: authorization in: header schema: type: string - name: user-agent in: header schema: type: string responses: '200': description: OK '400': description: Bad Request '403': description: Forbidden /api/status: get: description: '' responses: '200': description: OK components: schemas: CurrentUser: type: object properties: _id: type: string example: '' email: type: string example: johndoe@gmail.com firstName: type: string example: John lastName: type: string example: Doe publicKey: type: string example: johns_nacl_public_key encryptedPrivateKey: type: string example: johns_enc_nacl_private_key iv: type: string example: iv_of_enc_nacl_private_key tag: type: string example: tag_of_enc_nacl_private_key updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' Membership: type: object properties: user: type: object properties: _id: type: string example: '' email: type: string example: johndoe@gmail.com firstName: type: string example: John lastName: type: string example: Doe publicKey: type: string example: johns_nacl_public_key updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' workspace: type: string example: '' role: type: string example: admin MembershipOrg: type: object properties: user: type: object properties: _id: type: string example: '' email: type: string example: johndoe@gmail.com firstName: type: string example: John lastName: type: string example: Doe publicKey: type: string example: johns_nacl_public_key updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' organization: type: string example: '' role: type: string example: owner status: type: string example: accepted Organization: type: object properties: _id: type: string example: '' name: type: string example: Acme Corp. customerId: type: string example: '' Project: type: object properties: name: type: string example: My Project organization: type: string example: '' environments: type: array items: type: object properties: name: type: string example: development slug: type: string example: dev ProjectKey: type: object properties: encryptedkey: type: string example: '' nonce: type: string example: '' sender: type: object properties: publicKey: type: string example: senders_nacl_public_key receiver: type: string example: '' workspace: type: string example: '' CreateSecret: type: object properties: type: type: string example: shared secretKeyCiphertext: type: string example: '' secretKeyIV: type: string example: '' secretKeyTag: type: string example: '' secretValueCiphertext: type: string example: '' secretValueIV: type: string example: '' secretValueTag: type: string example: '' secretCommentCiphertext: type: string example: '' secretCommentIV: type: string example: '' secretCommentTag: type: string example: '' UpdateSecret: type: object properties: id: type: string example: '' secretKeyCiphertext: type: string example: '' secretKeyIV: type: string example: '' secretKeyTag: type: string example: '' secretValueCiphertext: type: string example: '' secretValueIV: type: string example: '' secretValueTag: type: string example: '' secretCommentCiphertext: type: string example: '' secretCommentIV: type: string example: '' secretCommentTag: type: string example: '' Secret: type: object properties: _id: type: string example: '' version: type: number example: 1 workspace: type: string example: '' type: type: string example: shared user: {} secretKeyCiphertext: type: string example: '' secretKeyIV: type: string example: '' secretKeyTag: type: string example: '' secretValueCiphertext: type: string example: '' secretValueIV: type: string example: '' secretValueTag: type: string example: '' secretCommentCiphertext: type: string example: '' secretCommentIV: type: string example: '' secretCommentTag: type: string example: '' updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' Log: type: object properties: _id: type: string example: '' user: type: object properties: _id: type: string example: '' email: type: string example: johndoe@gmail.com firstName: type: string example: John lastName: type: string example: Doe workspace: type: string example: '' actionNames: type: array example: - addSecrets items: type: string actions: type: array items: type: object properties: name: type: string example: addSecrets user: type: string example: '' workspace: type: string example: '' payload: type: array items: type: object properties: oldSecretVersion: type: string example: '' newSecretVersion: type: string example: '' channel: type: string example: cli ipAddress: type: string example: 192.168.0.1 updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' SecretSnapshot: type: object properties: workspace: type: string example: '' version: type: number example: 1 secretVersions: type: array items: type: object properties: _id: type: string example: '' SecretVersion: type: object properties: _id: type: string example: '' secret: type: string example: '' version: type: number example: 1 workspace: type: string example: '' type: type: string example: shared user: type: string example: '' environment: type: string example: dev isDeleted: type: string example: '' secretKeyCiphertext: type: string example: '' secretKeyIV: type: string example: '' secretKeyTag: type: string example: '' secretValueCiphertext: type: string example: '' secretValueIV: type: string example: '' secretValueTag: type: string example: '' ServiceTokenData: type: object properties: _id: type: string example: '' name: type: string example: '' workspace: type: string example: '' environment: type: string example: '' user: type: object properties: _id: type: string example: '' firstName: type: string example: '' lastName: type: string example: '' expiresAt: type: string example: '2023-01-13T14:16:12.210Z' encryptedKey: type: string example: '' iv: type: string example: '' tag: type: string example: '' updatedAt: type: string example: '2023-01-13T14:16:12.210Z' createdAt: type: string example: '2023-01-13T14:16:12.210Z' securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: >- This security definition uses the HTTP 'bearer' scheme, which allows the client to authenticate using a JSON Web Token (JWT) that is passed in the Authorization header of the request. apiKeyAuth: type: apiKey in: header name: X-API-Key description: >- This security definition uses an API key, which is passed in the header of the request as the value of the "X-API-Key" header. The client must provide a valid key in order to access the API.