How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Venafi SSH Management APIs API

The SSH Management APIs allow to manage device keys and keysets. This interface is valid only if you purchased SSH Manager for Machines.All product-supported operations are exposed via this API, including key operations (addition, removal, and editing of keys), rotation and methods to get the actual state of data. For more information about the SSH objects, see the Web SDK Object class reference.

Venafi SSH Management APIs API is one of 58 APIs that Venafi publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include SSH Management APIs. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 36 operations across 35 paths, and defines 41 schemas. It is described by OpenAPI 3.2.0, at version 26.1.1.

Requests are made against 3 base URLs: /, https://REPLACEdnsnameME/, https://{dnsname}/.

36 operations 35 paths 41 schemas 2 GET34 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
26.1.1
Base URL
https://api.venafi.cloud
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Venafi SSH Management APIs API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (AccessToken). By default, every request must be authenticated.

Paths & Operations 36

Across 35 paths, the API surfaces 36 operations — 2 GET, 34 POST. Each is listed below with its method, path, parameters, and response codes.

SSH Management APIs 36

The SSH Management APIs allow to manage device keys and keysets. This interface is valid only if you purchased SSH Manager for Machines. All product-supported operations are expos…

GET
/vedsdk/ssh/rules
Search key authorization rules
Venafi_Ssh_WebSDK_SshRestService_GetAuthRules 7 params → 200500400
POST
/vedsdk/ssh/TestDeviceConnection
Returns connection status for provided devices
Venafi_Ssh_WebSDK_SshRestService_TestDeviceConnection body → 200
POST
/vedsdk/ssh/ImportKeyUsageData
Imports key usage from a Unix or Linux host syslog
Venafi_Ssh_WebSDK_SshRestService_ImportKeyUsageData body → 200403400401
POST
/vedsdk/ssh/KeyUsage
Finds all key usage records matching the specified filtering criteria
Venafi_Ssh_WebSDK_SshRestService_GetKeyUsages body → 200403400401
POST
/vedsdk/ssh/RemoveKey
Marks a key for deletion
Venafi_Ssh_WebSDK_SshRestService_Remove body → 200
POST
/vedsdk/ssh/CancelKeyOperation
Cancels any running key operation. Can also rollback a key to its original state
Venafi_Ssh_WebSDK_SshRestService_CancelKeyOperation body → 200
POST
/vedsdk/ssh/RetryKeyOperation
Retries any failing operation (addition, removal, editing) on specified key
Venafi_Ssh_WebSDK_SshRestService_RetryKeyOperation body → 200
POST
/vedsdk/ssh/Rotate
Starts Synchronous Rotation of a specific keyset
Venafi_Ssh_WebSDK_SshRestService_StartRotation body → 200
POST
/vedsdk/ssh/RotateNonBlocking
Submits Rotation request of specific keyset
Venafi_Ssh_WebSDK_SshRestService_StartRotationNonBlocking body → 200
POST
/vedsdk/ssh/RollbackNonBlocking
Submits Rollback request of specific keyset
Venafi_Ssh_WebSDK_SshRestService_StartRollbackNonBlocking body → 200
POST
/vedsdk/ssh/CancelRotation
Cancels rotation of the specified keyset if it is running, or rolls back the…
Venafi_Ssh_WebSDK_SshRestService_CancelRotation body → 200
POST
/vedsdk/ssh/RetryRotation
Retries rotation of specified keyset
Venafi_Ssh_WebSDK_SshRestService_RetryRotation body → 200
POST
/vedsdk/ssh/EditKeyOptions
Changes Source Restrictions, and Forced commands in an authorized keys file
Venafi_Ssh_WebSDK_SshRestService_EditKeyOptions body → 200
POST
/vedsdk/ssh/EditSelfServiceAuthorizedKey
Changes location, notes, Source Restrictions, and Forced commands in an…
Venafi_Ssh_WebSDK_SshRestService_EditSelfServiceAuthorizedKey body → 200
POST
/vedsdk/ssh/AddSelfServicePrivateKey
Assigns an existing keyset to a policy folder
Venafi_Ssh_WebSDK_SshRestService_AddSelfServicePrivateKey body → 200
POST
/vedsdk/ssh/AddSelfServiceAuthorizedKey
Add an authorization key to a keyset
Venafi_Ssh_WebSDK_SshRestService_AddSelfServiceAuthorizedKey body → 200
POST
/vedsdk/ssh/ConfirmSelfServiceKeyInstallation
Verifies that a user manually installed a private key
Venafi_Ssh_WebSDK_SshRestService_ConfirmSelfServiceKeyInstallation body → 200
POST
/vedsdk/ssh/MoveKeysetsToPolicy
Moves a list of keysets to a policy folder
Venafi_Ssh_WebSDK_SshRestService_MoveKeysetsToPolicy body → 200
POST
/vedsdk/ssh/ExportSelfServiceAuthorizedKey
Downloads an authorized key
Venafi_Ssh_WebSDK_SshRestService_ExportSelfServiceAuthorizedKey body → 200
POST
/vedsdk/ssh/ExportSelfServicePrivateKey
Downloads a private key
Venafi_Ssh_WebSDK_SshRestService_ExportSelfServicePrivateKey body → 200
POST
/vedsdk/ssh/SkipKeyRotation
Skip key rotation
Venafi_Ssh_WebSDK_SshRestService_SkipKeyRotation body → 200
POST
/vedsdk/ssh/AddUserPrivateKey
Installs a new user private key on a device
Venafi_Ssh_WebSDK_SshRestService_AddUserPrivateKey body → 200
POST
/vedsdk/ssh/AddHostPrivateKey
Creates and installs a new private key on a host device
Venafi_Ssh_WebSDK_SshRestService_AddHostPrivateKey body → 200
POST
/vedsdk/ssh/AddAuthorizedKey
Creates an Open SSH Authorized key for provisioning to a device
Venafi_Ssh_WebSDK_SshRestService_AddAuthorizedKey body → 200
POST
/vedsdk/ssh/AddKnownHostKey
Creates a public key for a host
Venafi_Ssh_WebSDK_SshRestService_AddKnownHostKey body → 200
POST
/vedsdk/ssh/ImportAuthorizedKey
Adds or reuses a Base64 public key for a device
Venafi_Ssh_WebSDK_SshRestService_ImportAuthorizedKey body → 200
POST
/vedsdk/ssh/ImportPrivateKey
Adds or reuses a Base64 private key for a device
Venafi_Ssh_WebSDK_SshRestService_ImportPrivateKey body → 200
POST
/vedsdk/ssh/ChangePrivateKeyPassphrase
Changes the private key passphrase for a keyset
Venafi_Ssh_WebSDK_SshRestService_ChangePrivateKeyPassphrase body → 200
POST
/vedsdk/ssh/SetUnmatchedKeysetPassphrase
Sets the passphrase on a keyset that is missing the encrypted private key
Venafi_Ssh_WebSDK_SshRestService_SetUnmatchedKeysetPasshrase body → 200
POST
/vedsdk/ssh/DeleteUnmatchedKeyset
Deletes an unmatched keyset that is missing the encrypted private key…
Venafi_Ssh_WebSDK_SshRestService_DeleteUnmatchedKeyset body → 200
POST
/vedsdk/ssh/KeyDetails
Returns detailed key data
Venafi_Ssh_WebSDK_SshRestService_GetKeyDetails body → 200
POST
/vedsdk/ssh/Devices
Finds devices in the Policy tree that match the filtering criteria
Venafi_Ssh_WebSDK_SshRestService_GetDevices body → 200
GET
/vedsdk/ssh/KeysetDetails
Provides information about every device that shares the same keyset
Venafi_Ssh_WebSDK_SshRestService_GetKeysetDetail 2 params → 200
POST
/vedsdk/ssh/KeysetDetails
Returns private and public key pairs that identify details about a device
Venafi_Ssh_WebSDK_SshRestService_GetKeysetDetails body → 200
POST
/vedsdk/ssh/ApproveKeyOperation
Approves any key operation that has a Pending Approval status in a workflow
Venafi_Ssh_WebSDK_SshRestService_ApproveKeyOperation body → 200
POST
/vedsdk/ssh/RejectKeyOperation
Rejects any key operation that has a Pending Approval status in a workflow
Venafi_Ssh_WebSDK_SshRestService_RejectKeyOperation body → 200

Schemas 41

The contract defines 41 schemas that model the data the API accepts and returns. The most detailed are Ssh_WebSDK_DataContract_KeysetData (15 properties), Ssh_WebSDK_DataContract_Requests_AddSelfServiceAuthorizedKeyWebRequest (10 properties), Ssh_WebSDK_DataContract_Requests_AddAuthorizedKeyWebRequest (10 properties), Ssh_WebSDK_DataContract_Requests_SshLoadDataRequest (8 properties). Each schema is shown below with its type and property counts.

Ssh_WebSDK_DataContract_Requests_AddSelfServiceAuthorizedKeyWebRequest
object
The class for adding selfservice authorized key request.
10 properties
IList_1_Ssh_WebSDK_DataContract_KeyData_
array
Ssh_WebSDK_DataContract_Requests_UnmatchedKeysetRequest
object
The class for working with unmatched encrypted keyset
2 properties
Ssh_WebSDK_DataContract_Requests_PrivateKeyData
object
The class for importing private key request.
6 properties
Ssh_WebSDK_DataContract_Requests_ExportSelfServicePrivateKeyRequest
object
The class for exporting selfservice key request.
3 properties
Ssh_WebSDK_DataContract_ImportResponse
object
The class for importing key response.
2 properties
Ssh_WebSDK_DataContract_Requests_AddSelfServicePrivateKeyWebRequest
object
The class for adding selfservice private key request.
6 properties
Ssh_WebSDK_DataContract_SshWebResponse
object
Contains the response information for arbitrary action.
3 properties
Ssh_WebSDK_DataContract_AddUserPrivateKeyWebResponse
object
The class for adding user private key response.
3 properties
Ssh_WebSDK_DataContract_Requests_SshLoadDataRequest_KeyUsage
object
3 properties 3 required
Ssh_WebSDK_DataContract_Requests_ChangePrivateKeyPassphraseRequest
object
To change parivate key passphrase
2 properties
Ssh_WebSDK_DataContract_Requests_KeysetToPolicyWebRequest
object
The class for keyset to policy migration.
3 properties
Ssh_WebSDK_DataContract_AddHostPrivateKeyWebResponse
object
The class for adding host private key response.
3 properties
Ssh_WebSDK_DataContract_Requests_KeyOptionsWebRequest
object
The class for key options request.
5 properties
Ssh_WebSDK_DataContract_Requests_SshLoadDataRequest
object
Data object
8 properties
Web_SDK_Authentication_OAuthError
object
REST OAuth Error Response
2 properties
Ssh_WebSDK_DataContract_Requests_KeySetWebRequest
object
The class for keyset request.
1 property
ProductLogic_Ssh_Entities_PolicyViolation
integer
1: IsRootAccessOrphan Root access orphan 2: IsClientAccessOrphan Client access orphan 3: IsPrivateKeyOrphan Private key orphan 4: IsKnownHostOrphan Known host…
Ssh_WebSDK_DataContract_PageResponse_1_Ssh_WebSDK_DataContract_SshDeviceData_
object
Contains the response information for paginated queries.
1 property
IList_1_Ssh_WebSDK_DataContract_TestDeviceConnectionResult_
array
Ssh_WebSDK_DataContract_Requests_KeyUsageData
object
The class for key usage request.
1 property
Ssh_WebSDK_DataContract_AddSelfServiceKeyWebResponse
object
The class for adding selfservice private key response.
4 properties
Ssh_WebSDK_DataContract_PageResponse_1_Ssh_WebSDK_DataContract_KeysetData_
object
Contains the response information for paginated queries.
1 property
Ssh_WebSDK_AuthRulesResponse
object
Result class containing list of key authorization rules as well as paging links and count information.
4 properties
Ssh_WebSDK_DataContract_KeysetData
object
Stores detailed SSH keyset information.
15 properties
Ssh_WebSDK_DataContract_Requests_AddUserPrivateKeyWebRequest
object
The class for adding user private key request.
7 properties
Ssh_WebSDK_DataContract_Requests_EditSelfServiceAuthorizedKeyWebRequest
object
The class for editing selfservice authorized key request.
6 properties
Ssh_WebSDK_DataContract_ExportSelfServiceKeyResponse
object
The class for exporting selfservice key response.
2 properties
Ssh_WebSDK_DataContract_AddKeyWebResponse
object
The class for adding key response.
2 properties
Ssh_WebSDK_DataContract_Requests_AddHostPrivateKeyWebRequest
object
The class for adding host private key request.
6 properties
Ssh_WebSDK_DataContract_Requests_ExportSelfServiceKeyRequest
object
The class for exporting selfservice key request.
2 properties
Ssh_WebSDK_DataContract_Requests_AddAuthorizedKeyWebRequest
object
The class for adding authorized key request.
10 properties
Ssh_WebSDK_DataContract_KeyProcessStatus
integer
0: NoStatus Indicates that no status is available for the key. 1: Provisioning Indicates that key is being provisioned (added or edited) to its device. 2: Remo…
Ssh_WebSDK_DataContract_KeysetProcessStatus
integer
5: Rotating Indicates that keyset is being rotated. 6: FailedToRotate Indicates that keyset had error during rotation. 7: KeyOperationRunning Indicates that at…
Ssh_WebSDK_DataContract_PageResponse_1_Ssh_WebSDK_DataContract_SshKeyUsageData_
object
Contains the response information for paginated queries.
1 property
Nullable_1_Ssh_WebSDK_DataContract_SshKeyUsageAlert_
integernull
1: UntrackedKey Untracked key. 2: UnknownClient Unknown client.
Ssh_WebSDK_DataContract_Requests_AddKnownHostKeyWebRequest
object
The class for adding knownhost key request.
5 properties
Ssh_WebSDK_DataContract_Requests_KeyWebRequest
object
The class for key request.
1 property
Ssh_WebSDK_DataContract_Requests_UnmatchedKeysetDeleteRequest
object
The class for working with a deletion of a unmatched encrypted keyset
1 property
Ssh_WebSDK_DataContract_Requests_AuthorizedKeyData
object
The class for importing authorized key request.
5 properties
Ssh_WebSDK_DataContract_Requests_WorkflowKeyOperationRequest
object
The class for workflow key operation request.
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

venafi-ssh-management-apis-api-openapi.yml Raw ↑

Other APIs Venafi publishes across the network.

Venafi Access Management APIs API
Venafi AlgorithmSelector APIs API
Venafi Application API
Venafi Authentication Server APIs API
Venafi Certificate Approvals API
Venafi Certificate Auto-renewal Monitoring API
Venafi Certificate Discovery API
Venafi Certificate Expiration Reports API
Venafi Certificate Import API
Venafi Certificate Installations API
Venafi Certificate Inventory Monitoring API
Venafi Certificate Management APIs API
Where this information came from

This is an independent, third-party profile of Venafi SSH Management APIs API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.