How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

OpenAI Vaults API

The Vaults API from OpenAI — 4 operation(s) for vaults.

OpenAI Vaults API is one of 62 APIs that OpenAI publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 6 JSON Schema definitions.

Tagged areas include Vault. The published artifact set on APIs.io includes an OpenAPI specification, a GitHub repository, and 6 JSON Schemas.

This API exposes 9 operations across 4 paths, and defines 46 schemas. It is described by OpenAPI 3.2.0, at version 2.3.0.

Requests are made against a single base URL, https://api.openai.com/v1.

9 operations 4 paths 46 schemas 2 DELETE4 GET3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.3.0
Base URL
https://api.openai.com
Authentication
HTTP Bearer, HTTP Bearer
License
MIT
Terms of Service
Resource Areas
1

Authentication & Security 2

OpenAI Vaults API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (ApiKeyAuth). It accepts HTTP bearer tokens (AdminApiKeyAuth). By default, every request must be authenticated.

Paths & Operations 9

Across 4 paths, the API surfaces 9 operations — 2 DELETE, 4 GET, 3 POST. Each is listed below with its method, path, parameters, and response codes.

Vaults 9
GET
/vaults
List vaults
listVaults 4 params → 200400401403404409500503
POST
/vaults
Create a vault
createVault body → 201400401403404409500503
GET
/vaults/{vault_id}
Retrieve a vault
retrieveVault 1 param → 200400401403404409500503
DELETE
/vaults/{vault_id}
Delete a vault
deleteVault 1 param → 200400401403404409500503
GET
/vaults/{vault_id}/credentials
List vault credentials
listVaultCredentials 5 params → 200400401403404409500503
POST
/vaults/{vault_id}/credentials
Create a vault credential
createVaultCredential 1 param body → 201400401403404409500503
GET
/vaults/{vault_id}/credentials/{credential_id}
Retrieve a vault credential
retrieveVaultCredential 2 params → 200400401403404409500503
POST
/vaults/{vault_id}/credentials/{credential_id}
Update a vault credential
rotateVaultCredential 2 params body → 200400401403404409500503
DELETE
/vaults/{vault_id}/credentials/{credential_id}
Delete a vault credential
deleteVaultCredential 2 params → 200400401403404409500503

Schemas 46

The contract defines 46 schemas that model the data the API accepts and returns. The most detailed are VaultCredentialResource (8 properties), CreateMcpOauthRefreshParam (6 properties), VaultResource (5 properties), VaultListResource (5 properties). Each schema is shown below with its type and property counts.

RotateVaultCredentialAuthParamMcpOauth
object
Rotate an OAuth credential for an HTTPS MCP destination.
4 properties 1 required
RotateMcpOauthTokenEndpointAuthParamClientSecretPost
object
Updates credentials sent in the token request body.
2 properties 1 required
RotateVaultCredentialAuthParam
Updates to a vault credential without changing its authentication method or destination configuration.
McpOauthTokenEndpointAuthResourceNone
object
Sends the client ID without a client secret.
1 property 1 required
VaultCredentialNetworkingResourceLimited
object
Allows substitution only for the listed hosts. The environment network policy must also allow these hosts.
2 properties 2 required
CreateVaultParams
object
Parameters for creating a vault to store credentials used by agent tools.
2 properties
VaultCredentialNetworkingParamLimited
object
Allows substitution only for the listed hosts. The environment network policy must also allow these hosts.
2 properties 2 required
CreateMcpOauthTokenEndpointAuthParam
Client authentication credentials for OAuth token refresh.
RotateVaultCredentialAuthParamEnvironmentVariable
object
Replace the secret for an OpenAI-hosted environment credential. The environment variable name and networking configuration remain unchanged.
2 properties 2 required
VaultCredentialResource
object
Metadata for a stored credential. Secret values are never returned.
8 properties 8 required
VaultCredentialListResource
object
A page of Agents API resources, with IDs for retrieving additional pages.
5 properties 5 required
RotateVaultCredentialAuthParamStaticBearer
object
Replace the bearer token for the credential's MCP server.
2 properties 2 required
ErrorResponse-2
object
An API error response.
1 property 1 required
ListOrderParam
string
The order in which paginated resources are returned.
VaultCredentialNetworkingParam
Destination permissions for an environment-variable credential. These do not grant network access to the environment.
VaultCredentialNetworkingResourceUnrestricted
object
Allows substitution for destinations permitted by the environment network policy. Requires environment.network.access to be restricted, with explicit alloweddo…
1 property 1 required
RotateMcpOauthRefreshParam
object
Updates to an MCP credential's existing OAuth refresh configuration.
3 properties
McpOauthRefreshResource
object
Configuration used to refresh an MCP OAuth access token, excluding secret values.
5 properties 5 required
VaultCredentialAuthResource
The authentication configuration of a vault credential, excluding secrets.
CreateMcpOauthTokenEndpointAuthParamNone
object
Sends the client ID without a client secret.
1 property 1 required
VaultCredentialAuthResourceStaticBearer
object
Metadata for a bearer-token credential, without automatic OAuth refresh.
2 properties 2 required
VaultCredentialAuthResourceMcpOauth
object
Public metadata for an OAuth credential; tokens and client secrets are never returned.
4 properties 4 required
CreateMcpOauthTokenEndpointAuthParamClientSecretPost
object
Sends the client ID and secret in the token request body.
2 properties 2 required
CreateVaultCredentialAuthParamStaticBearer
object
A bearer token for an MCP server, without automatic OAuth refresh.
3 properties 3 required
RotateMcpOauthTokenEndpointAuthParam
Client-secret updates that preserve the credential's OAuth authentication method.
RotateVaultCredentialParams
object
Metadata, secret, expiry, and OAuth refresh scope updates for an existing vault credential. Supply at least one of auth or metadata.
2 properties
VaultCredentialAuthResourceEnvironmentVariable
object
Metadata for an HTTP credential used only in OpenAI-hosted environments. Sandbox code receives a placeholder. The proxy substitutes the secret for allowed HTTP…
3 properties 3 required
CreateVaultCredentialParams
object
Parameters for storing a credential for an MCP server or an OpenAI-hosted environment.
3 properties 2 required
McpOauthTokenEndpointAuthResourceClientSecretPost
object
Sends the client ID and secret in the token request body.
1 property 1 required
ErrorBodyResource
object
Details about an API error.
4 properties 4 required
VaultStatusFilterParam
One or more lifecycle statuses to include when listing vaults or credentials.
VaultStatusParam
string
Whether a vault or credential is active or archived.
VaultResource
object
A collection of credentials for MCP servers and OpenAI-hosted environments.
5 properties 5 required
DeletedVaultCredentialResource
object
Confirmation that a vault credential was deleted.
3 properties 3 required
CreateVaultCredentialAuthParamMcpOauth
object
An OAuth credential for an HTTPS MCP destination.
5 properties 3 required
RotateMcpOauthTokenEndpointAuthParamClientSecretBasic
object
Updates credentials sent using HTTP Basic authentication.
2 properties 1 required
CreateVaultCredentialAuthParamEnvironmentVariable
object
An HTTP credential for OpenAI-hosted environments only. The sandbox receives an environment variable containing a placeholder, not the secret. Use the placehol…
4 properties 4 required
VaultCredentialNetworkingResource
Destination permissions for an environment-variable credential. These do not grant network access to the environment.
VaultCredentialNetworkingParamUnrestricted
object
Allows substitution for destinations permitted by the environment network policy. Requires environment.network.access to be restricted, with explicit alloweddo…
1 property 1 required
McpOauthTokenEndpointAuthResource
The client authentication method used for OAuth token refresh.
CreateMcpOauthTokenEndpointAuthParamClientSecretBasic
object
Sends the client ID and secret using HTTP Basic authentication.
2 properties 2 required
McpOauthTokenEndpointAuthResourceClientSecretBasic
object
Sends the client ID and secret using HTTP Basic authentication.
1 property 1 required
DeletedVaultResource
object
Confirmation that a vault was deleted.
3 properties 3 required
VaultListResource
object
A page of Agents API resources, with IDs for retrieving additional pages.
5 properties 5 required
CreateVaultCredentialAuthParam
Authentication credentials for an MCP server or an OpenAI-hosted environment.
CreateMcpOauthRefreshParam
object
Configuration for refreshing the access token of an MCP OAuth credential.
6 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

openai-vaults-api-openapi.yml Raw ↑

Other APIs OpenAI publishes across the network.

OpenAI Responses API
OpenAI Moderations API
OpenAI Batch API
OpenAI Vector Stores API
OpenAI Uploads API
OpenAI Realtime API
OpenAI Evals API
OpenAI Videos API
OpenAI Conversations API
OpenAI Containers API
OpenAI ChatKit API
OpenAI Skills API
Where this information came from

This is an independent, third-party profile of OpenAI Vaults API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.