OpenAI Vaults API is one of 62 APIs that OpenAI publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
This API exposes 6 JSON Schema definitions.
Tagged areas include Vault. The published artifact set on APIs.io includes an OpenAPI specification, a GitHub repository, and 6 JSON Schemas.
This API exposes
9 operations
across 4 paths,
and defines 46 schemas.
It is described by OpenAPI 3.2.0, at version 2.3.0.
Requests are made against a single base URL, https://api.openai.com/v1.
The identity and technical contract details declared by the specification.
RotateVaultCredentialAuthParamMcpOauth
object
Rotate an OAuth credential for an HTTPS MCP destination.
4 properties
1 required
RotateMcpOauthTokenEndpointAuthParamClientSecretPost
object
Updates credentials sent in the token request body.
2 properties
1 required
RotateVaultCredentialAuthParam
Updates to a vault credential without changing its authentication method or destination configuration.
McpOauthTokenEndpointAuthResourceNone
object
Sends the client ID without a client secret.
1 property
1 required
VaultCredentialNetworkingResourceLimited
object
Allows substitution only for the listed hosts. The environment network policy must also allow these hosts.
2 properties
2 required
CreateVaultParams
object
Parameters for creating a vault to store credentials used by agent tools.
2 properties
VaultCredentialNetworkingParamLimited
object
Allows substitution only for the listed hosts. The environment network policy must also allow these hosts.
2 properties
2 required
CreateMcpOauthTokenEndpointAuthParam
Client authentication credentials for OAuth token refresh.
RotateVaultCredentialAuthParamEnvironmentVariable
object
Replace the secret for an OpenAI-hosted environment credential. The environment variable name and networking configuration remain unchanged.
2 properties
2 required
VaultCredentialResource
object
Metadata for a stored credential. Secret values are never returned.
8 properties
8 required
VaultCredentialListResource
object
A page of Agents API resources, with IDs for retrieving additional pages.
5 properties
5 required
RotateVaultCredentialAuthParamStaticBearer
object
Replace the bearer token for the credential's MCP server.
2 properties
2 required
ErrorResponse-2
object
An API error response.
1 property
1 required
ListOrderParam
string
The order in which paginated resources are returned.
VaultCredentialNetworkingParam
Destination permissions for an environment-variable credential. These do not grant network access to the environment.
VaultCredentialNetworkingResourceUnrestricted
object
Allows substitution for destinations permitted by the environment network policy. Requires environment.network.access to be restricted, with explicit alloweddo…
1 property
1 required
RotateMcpOauthRefreshParam
object
Updates to an MCP credential's existing OAuth refresh configuration.
3 properties
McpOauthRefreshResource
object
Configuration used to refresh an MCP OAuth access token, excluding secret values.
5 properties
5 required
VaultCredentialAuthResource
The authentication configuration of a vault credential, excluding secrets.
CreateMcpOauthTokenEndpointAuthParamNone
object
Sends the client ID without a client secret.
1 property
1 required
VaultCredentialAuthResourceStaticBearer
object
Metadata for a bearer-token credential, without automatic OAuth refresh.
2 properties
2 required
VaultCredentialAuthResourceMcpOauth
object
Public metadata for an OAuth credential; tokens and client secrets are never returned.
4 properties
4 required
CreateMcpOauthTokenEndpointAuthParamClientSecretPost
object
Sends the client ID and secret in the token request body.
2 properties
2 required
CreateVaultCredentialAuthParamStaticBearer
object
A bearer token for an MCP server, without automatic OAuth refresh.
3 properties
3 required
RotateMcpOauthTokenEndpointAuthParam
Client-secret updates that preserve the credential's OAuth authentication method.
RotateVaultCredentialParams
object
Metadata, secret, expiry, and OAuth refresh scope updates for an existing vault credential. Supply at least one of auth or metadata.
2 properties
VaultCredentialAuthResourceEnvironmentVariable
object
Metadata for an HTTP credential used only in OpenAI-hosted environments. Sandbox code receives a placeholder. The proxy substitutes the secret for allowed HTTP…
3 properties
3 required
CreateVaultCredentialParams
object
Parameters for storing a credential for an MCP server or an OpenAI-hosted environment.
3 properties
2 required
McpOauthTokenEndpointAuthResourceClientSecretPost
object
Sends the client ID and secret in the token request body.
1 property
1 required
ErrorBodyResource
object
Details about an API error.
4 properties
4 required
VaultStatusFilterParam
One or more lifecycle statuses to include when listing vaults or credentials.
VaultStatusParam
string
Whether a vault or credential is active or archived.
VaultResource
object
A collection of credentials for MCP servers and OpenAI-hosted environments.
5 properties
5 required
DeletedVaultCredentialResource
object
Confirmation that a vault credential was deleted.
3 properties
3 required
CreateVaultCredentialAuthParamMcpOauth
object
An OAuth credential for an HTTPS MCP destination.
5 properties
3 required
RotateMcpOauthTokenEndpointAuthParamClientSecretBasic
object
Updates credentials sent using HTTP Basic authentication.
2 properties
1 required
CreateVaultCredentialAuthParamEnvironmentVariable
object
An HTTP credential for OpenAI-hosted environments only. The sandbox receives an environment variable containing a placeholder, not the secret. Use the placehol…
4 properties
4 required
VaultCredentialNetworkingResource
Destination permissions for an environment-variable credential. These do not grant network access to the environment.
VaultCredentialNetworkingParamUnrestricted
object
Allows substitution for destinations permitted by the environment network policy. Requires environment.network.access to be restricted, with explicit alloweddo…
1 property
1 required
McpOauthTokenEndpointAuthResource
The client authentication method used for OAuth token refresh.
CreateMcpOauthTokenEndpointAuthParamClientSecretBasic
object
Sends the client ID and secret using HTTP Basic authentication.
2 properties
2 required
McpOauthTokenEndpointAuthResourceClientSecretBasic
object
Sends the client ID and secret using HTTP Basic authentication.
1 property
1 required
DeletedVaultResource
object
Confirmation that a vault was deleted.
3 properties
3 required
VaultListResource
object
A page of Agents API resources, with IDs for retrieving additional pages.
5 properties
5 required
CreateVaultCredentialAuthParam
Authentication credentials for an MCP server or an OpenAI-hosted environment.
CreateMcpOauthRefreshParam
object
Configuration for refreshing the access token of an MCP OAuth credential.
6 properties
4 required
The full machine-readable OpenAPI contract behind this narrative.
Other APIs OpenAI publishes across the network.