REST API

Reference and language examples for the Agent Vault REST API — the fallback surface for any agent that isn't MCP-aware.

Every agent gets the same capability over a plain authenticated HTTP API, for runtimes that don't (yet) speak MCP: CI jobs, custom automations, or any language with a solid HTTP client.

  • Base URL: https://secretstash.cloud/api/v1/agents/{agent}/secrets
  • Auth: Authorization: Bearer <YOUR_AGENT_API_KEY> header
  • Content type: application/json

{agent} is the agent's UUID, shown on its page in the web application (also visible in the REST base URL under Connection on that page).

Endpoints

List available secrets

GET /api/v1/agents/{agent}/secrets

Returns metadata only — variable names and environment slugs the agent may resolve, never values:

{
  "data": [
    {
      "environment": { "id": "...", "name": "Production", "slug": "production" },
      "dek_provisioned": true,
      "variables": [{ "name": "GITHUB_PROD_TOKEN" }, { "name": "STRIPE_SECRET_KEY" }]
    }
  ]
}

Resolve a single secret

GET /api/v1/agents/{agent}/secrets/{name}?environment=<slug>

environment is optional — omit it to search across all of the agent's authorized environments (the first match wins). Returns:

{ "data": { "GITHUB_PROD_TOKEN": "ghp_..." } }

A name outside the agent's scope returns 404.

Resolve a batch of secrets

POST /api/v1/agents/{agent}/secrets/resolve
{
  "variables": ["GITHUB_PROD_TOKEN", "STRIPE_SECRET_KEY"],
  "environment": "production"
}

Returns all requested values in one response:

{ "data": { "GITHUB_PROD_TOKEN": "ghp_...", "STRIPE_SECRET_KEY": "sk_..." } }

Versioning

/api/v1/... is the canonical, supported path. An older unversioned fallback (/api/agents/..., no v1 segment) is served for backward compatibility, but every response through it carries deprecation headers: Deprecation: true, Sunset, Link: <.../api/v1/...>; rel="successor-version", and X-Api-Version: v1. New integrations should always use the versioned path.

Language examples

Every example below resolves GITHUB_PROD_TOKEN from the production environment using the single-secret endpoint.

curl -H "Authorization: Bearer $AGENT_API_KEY" \
  "https://secretstash.cloud/api/v1/agents/$AGENT_ID/secrets/GITHUB_PROD_TOKEN?environment=production"

Next steps