openapi: 3.0.3 info: title: CyberArk Conjur Manager Authentication Secrets API description: Conjur Secrets Manager is CyberArk's machine-identity and secrets management platform, available as Conjur Open Source, Conjur Enterprise (Self-Hosted), and Conjur Cloud (SaaS). The REST API enables authenticating hosts and users, loading and updating policies, storing and retrieving secrets, rotating credentials, managing public keys, and querying audit information. The canonical OpenAPI specification is published at github.com/cyberark/conjur-openapi-spec; this file is a curated profile of the most-used endpoints aligned with CyberArk Secrets Manager Self-Hosted and SaaS. version: '1.0' contact: name: CyberArk Developer url: https://developer.cyberark.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://conjur.example.com description: Conjur Self-Hosted appliance (replace with appliance hostname) - url: https://{tenant}.secretsmgr.cyberark.cloud/api description: Conjur Cloud tenant variables: tenant: default: tenant description: CyberArk Conjur Cloud tenant subdomain security: - ConjurAuth: [] tags: - name: Secrets description: Store and retrieve secret values bound to variable resources. paths: /secrets/{account}/{kind}/{identifier}: get: tags: - Secrets summary: Retrieve secret value operationId: retrieveSecret parameters: - name: account in: path required: true schema: type: string - name: kind in: path required: true schema: type: string enum: - variable - name: identifier in: path required: true schema: type: string - name: version in: query required: false schema: type: integer responses: '200': description: Secret value content: text/plain: schema: type: string '401': description: Unauthorized '404': description: Not found post: tags: - Secrets summary: Store secret value operationId: addSecret parameters: - name: account in: path required: true schema: type: string - name: kind in: path required: true schema: type: string enum: - variable - name: identifier in: path required: true schema: type: string requestBody: required: true content: text/plain: schema: type: string responses: '201': description: Secret stored components: securitySchemes: ConjurAuth: type: http scheme: bearer bearerFormat: ConjurAccessToken externalDocs: description: Conjur OpenAPI Specification (canonical) url: https://github.com/cyberark/conjur-openapi-spec