How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Venafi Credential Management API

The Credential Management API from Venafi — 7 operation(s) for credential management.

Venafi Credential Management API is one of 58 APIs that Venafi publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Credential Management. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 14 operations across 7 paths, and defines 77 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 6 base URLs: https://api.venafi.cloud, https://api.eu.venafi.cloud, https://api.au.venafi.cloud, https://api.uk.venafi.cloud, https://api.sg.venafi.cloud, https://api.ca.venafi.cloud.

14 operations 7 paths 77 schemas 3 DELETE4 GET5 POST2 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.venafi.cloud
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Venafi Credential Management API declares 2 security schemes for authenticating requests. An API key is passed in the header as service-account (service-account). An API key is passed in the header as tppl-api-key (tppl-api-key).

Paths & Operations 14

Across 7 paths, the API surfaces 14 operations — 3 DELETE, 4 GET, 5 POST, 2 PUT. Each is listed below with its method, path, parameters, and response codes.

Credential Management 14
GET
/v1/credentialmanagerconfigurations
Retrieves a set of Credential Manager Service configurations
get-public-cms-conf 1 param → 200400401403404500
POST
/v1/credentialmanagerconfigurations
Add a set of Credential Manager Service configurations
post-public-cms-conf body → 201400401403404500
PUT
/v1/credentialmanagerconfigurations
Update a Credential Manager Service configuration
put-public-cms-conf body → 200400401403404500
GET
/v1/credentialmanagerconfigurations/{id}
Retrieves a Credential Manager Service configuration by ID
get-public-cms-conf-id 1 param → 200400401403404500
DELETE
/v1/credentialmanagerconfigurations/{id}
Delete a Credential Manager Service configuration by ID
delete-public-cms-conf-id 1 param → 204400401403404500
POST
/v1/credentialmanagerconfigurations/test
Test the connection to a privileged access management
post-public-cms-conf-test body → 200400401403404500
POST
/v1/credentialmanagerconfigurations/{id}/test
Test the connection to an external Privilege Access Management by ID
post-public-cms-conf-test-id 1 param → 200400401403404500
GET
/v1/credentials
Retrieves credentials for a company
get-public-cms-credential 5 params → 200400401403422500
POST
/v1/credentials
Add a set of new shared credentials
post-public-cms-credential body → 201400401403422500
PUT
/v1/credentials
Update a shared credential
put-public-cms-credential body → 200400401403422500
DELETE
/v1/credentials
Delete shared credentials
delete-public-cms-credential 1 param → 200400401403422500
GET
/v1/credentials/{id}
Retrieves shared credential by ID
get-public-cms-credential-id 2 params → 200400401403422500
DELETE
/v1/credentials/{id}
Delete shared credential by ID
delete-public-cms-credential-id 1 param → 204400401403422500
POST
/v1/credentials/test
Test the access to shared credential by ID
post-public-cms-credential-test-id body → 200400401403404500

Schemas 77

The contract defines 77 schemas that model the data the API accepts and returns. The most detailed are CredentialResponse (13 properties), CMSConfigurationResponse (12 properties), UpdateCMSConfigurationRequest (6 properties), CreateCMSConfigurationRequest (6 properties). Each schema is shown below with its type and property counts.

CertificateCredentialData
object
4 properties
CreatedBy
string
The ID of the user whom created the credential.
GetCredentialsResponse
object
Array of credentials received.
2 properties 2 required
CreateCMSConfigurationsRequest
object
The array of Credential Manager Service configurations to create.
1 property 1 required
HashiCorpDetails
object
The HashiCorp Credential information.
2 properties
TokenAuthenticationData
object
1 property
CreateHashiCorpDetails
UpdateCMSConfigurationRequest
object
The information representing a Credential Manager Service configuration for update.
6 properties 1 required
CyberArkDetails
object
The CyberArk Credential information.
3 properties
UpdateCredentialRequest
object
The properties representing a credential to update.
5 properties 1 required
DeleteCredentialsResponse
object
The response for the delete credentials action.
2 properties 2 required
TeamsIds
array
The ID's of teams.
CreateCredentialDetails
Reference
object
The machine referenced.
2 properties 2 required
CreateCyberArkDetails
TSGId
string
The TSG identifier the credential belongs to.
CreateCMSConfigurationsResponse
object
The array of Credential Manager Service configurations created.
2 properties 2 required
CMSAuthenticationType
string
The authentication type for the privileged access management: certificate - For authentication with a Certificate bundle userPassword - For authentication with…
CreateHashiCorpCredDetails
CompanyId
string
The company ID
TestCMSConfigurationRequest
object
The information representing a Credential Manager Service configuration for test purposes.
6 properties 1 required
ResponseCyberArkDetails
TestHashiCorpDetails
Name
string
The Name of CMS configuration
TestCredentialRequest
object
The properties representing a credential to test.
5 properties 1 required
AddCredentialsResponse
object
The response for the add credentials action.
2 properties 2 required
CyberArkConfigurationRequiredProp
The configuration for the CyberArk app. It's required to set the value for the cmsType property to cyberark.
2 required
UpdateHashiCorpCredDetails
CredentialResponse
object
The properties representing a Credential for response purposes.
13 properties 5 required
HashiCorpDetailsRequiredProp
2 required
CreatedOn
string
The date in ISO 8601 full-date format when the credential was created.
TestCyberArkDetails
AddCredentialRequest
object
The properties representing a credential to add.
6 properties 4 required
AuthType
string
The type of the authentication: password usernamepassword
LastModifiedBy
string
The ID of the user whom modified the credential.
GetCMSConfigurationsResponse
object
The array of Credential Manager Service configurations received.
2 properties 2 required
TestCyberArkCredDetails
TestCMSDetails
CreateCMSDetails
CredentialId
string
The ID of the Credential in our System.
ReferenceType
string
The type of the reference: machine
CreateCyberArkCredDetails
ErrorResponse5
object
Holds the response body returned for errors.
1 property
CyberArkConfiguration
The configuration for the CyberArk app. It's required to set the value for the cmsType property to cyberark.
TestHashiCorpCredDetails
ResponseHashiCorpDetails
ResponseCyberArkCredDetails
UpdateCMSDetails
TeamId
string
The ID of a team.
TestCredentialResponse
object
The result of testing access to the credential.
2 properties 2 required
VSatelliteIds
array
An array of the VSatellite Ids which are connected to the CMS provider.
CMSConfId
string
The Credential Manager Service configuration ID.
VSatelliteId
string
The VSatellite ID
CredentialName
string
The name of the Credential in our System.
ResponseCredentialDetails
ResponseHashiCorpCredDetails
UpdateCyberArkCredDetails
CMSType
string
The type of the privileged access management: cyberark - For CyberArk privileged access management hashicorp - For HashiCorp privileged access management
LastModifiedOn
string
The date in ISO 8601 full-date format when the credential was modified.
AppId
string
The application ID from the CyberArk provider.
HashiCorpConfiguration
The configuration for the HashiCorp app. It's required to set the value for the cmsType property to hashicorp.
References
array
The machines referenced.
Error2
object
Hold the error details.
3 properties 2 required
CMSConfigurationResponse
object
The information representing a Credential Manager Service configuration for response.
12 properties
TestCMSConfigurationResponse
object
The result of testing the Credential Manager Service configuration.
2 properties 2 required
CMSURL
string
The baseUrl of the privileged access management provider.
HashiCorpConfigurationRequiredProp
The configuration for the HashiCorp app. It's required to set the value for the cmsType property to hashicorp.
1 required
ResponseCMSDetails
An string containing the JSON content representing the details of the specific privileged access management.
UpdateCyberArkDetails
CyberArkDetailsRequiredProp
2 required
UserPasswordAuthenticationData
object
2 properties
AppRoleAuthenticationData
object
2 properties
CreateCMSConfigurationRequest
object
The information representing a Credential Manager Service configuration for creation purpose.
6 properties 3 required
TestCredentialDetails
UpdateCredentialDetails
UpdateHashiCorpDetails
AddCredentialsRequest
object
Array of credentials to add.
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

venafi-credential-management-api-openapi.yml Raw ↑

Other APIs Venafi publishes across the network.

Venafi Access Management APIs API
Venafi AlgorithmSelector APIs API
Venafi Application API
Venafi Authentication Server APIs API
Venafi Certificate Approvals API
Venafi Certificate Auto-renewal Monitoring API
Venafi Certificate Discovery API
Venafi Certificate Expiration Reports API
Venafi Certificate Import API
Venafi Certificate Installations API
Venafi Certificate Inventory Monitoring API
Venafi Certificate Management APIs API
Where this information came from

This is an independent, third-party profile of Venafi Credential Management API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.