openapi: 3.2.0 info: title: Dependency Track Secrets API version: 2.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track email: dependencytrack@owasp.org license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged Secrets across 2 of this provider''s published API definitions: dependency-track-openapi-v2.yaml, dependency-track-v2-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api/v2 security: - apiKeyAuth: [] - bearerAuth: [] tags: - name: Secrets description: Endpoints related to secrets paths: /secrets: get: tags: - Secrets summary: List secret metadata description: 'Returns a paginated list of secret metadata. Requires the `SYSTEM_CONFIGURATION` or `SYSTEM_CONFIGURATION_READ` permission.' operationId: listSecretMetadata parameters: - name: q in: query description: Optional search text to filter secrets by. Filtering uses case-insensitive "starts with" semantics on the secret name. schema: type: string - name: page_token in: query description: Opaque token pointing to a specific position in a collection schema: type: string - name: limit in: query description: Maximum number of items to retrieve from the collection schema: maximum: 1000 minimum: 1 type: integer format: int32 default: 100 responses: '200': description: Paginated list of secret metadata content: application/json: schema: $ref: '#/components/schemas/list-secrets-response' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' default: $ref: '#/components/responses/generic-error' post: tags: - Secrets summary: Create a secret description: 'Creates a new secret. Requires the `SECRET_MANAGEMENT` or `SECRET_MANAGEMENT_CREATE` permission. Administrators can configure the secret manager to be read-only. In that case, create requests will be rejected with status code `400`.' operationId: createSecret requestBody: content: application/json: schema: $ref: '#/components/schemas/create-secret-request' required: true responses: '201': description: Secret created headers: Location: description: URL of the created secret schema: type: string format: uri '400': description: Bad Request content: application/problem+json: schema: anyOf: - $ref: '#/components/schemas/invalid-request-problem-details' - $ref: '#/components/schemas/problem-details' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' '409': $ref: '#/components/responses/generic-conflict-error' default: $ref: '#/components/responses/generic-error' servers: - url: /api/v2 /secrets/{name}: get: tags: - Secrets summary: Get secret metadata description: 'Returns metadata about a given secret. Requires the `SYSTEM_CONFIGURATION` or `SYSTEM_CONFIGURATION_READ` permission.' operationId: getSecretMetadata parameters: - name: name in: path description: The name of the secret required: true schema: $ref: '#/components/schemas/secret-name' responses: '200': description: Secret metadata content: application/json: schema: $ref: '#/components/schemas/secret-metadata' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' '404': $ref: '#/components/responses/generic-not-found-error' default: $ref: '#/components/responses/generic-error' delete: tags: - Secrets summary: Delete a secret description: 'Deletes an existing secret. Requires the `SECRET_MANAGEMENT` or `SECRET_MANAGEMENT_DELETE` permission. Administrators can configure the secret manager to be read-only. In that case, delete requests will be rejected with status code `400`.' operationId: deleteSecret parameters: - name: name in: path description: The name of the secret required: true schema: $ref: '#/components/schemas/secret-name' responses: '204': description: Secret deleted '400': description: Bad Request content: application/problem+json: schema: anyOf: - $ref: '#/components/schemas/invalid-request-problem-details' - $ref: '#/components/schemas/problem-details' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' '404': $ref: '#/components/responses/generic-not-found-error' default: $ref: '#/components/responses/generic-error' patch: tags: - Secrets summary: Update a secret description: 'Updates an existing secret. Requires the `SECRET_MANAGEMENT` or `SECRET_MANAGEMENT_UPDATE` permission. Administrators can configure the secret manager to be read-only. In that case, update requests will be rejected with status code `400`.' operationId: updateSecret parameters: - name: name in: path description: The name of the secret required: true schema: $ref: '#/components/schemas/secret-name' requestBody: content: application/json: schema: $ref: '#/components/schemas/update-secret-request' required: true responses: '204': description: Secret updated '304': description: Not modified '400': description: Bad Request content: application/problem+json: schema: anyOf: - $ref: '#/components/schemas/invalid-request-problem-details' - $ref: '#/components/schemas/problem-details' '401': $ref: '#/components/responses/generic-unauthorized-error' '403': $ref: '#/components/responses/generic-forbidden-error' '404': $ref: '#/components/responses/generic-not-found-error' default: $ref: '#/components/responses/generic-error' servers: - url: /api/v2 components: schemas: total-count-type: type: string enum: - AT_LEAST - EXACT paginated-response: required: - total type: object properties: next_page_token: type: string description: Token to retrieve the next page. Absent when no more items exist. total: $ref: '#/components/schemas/total-count' x-parent: true create-secret-request: required: - name - value type: object properties: name: $ref: '#/components/schemas/secret-name' description: maxLength: 255 type: string value: maxLength: 4096 minLength: 1 type: string secret-name: pattern: ^[a-zA-Z0-9_-]{1,64}$ type: string example: MY_SECRET constraint-violation-error: required: - message type: object properties: path: type: string description: Path to the invalid field in the request value: type: string description: The invalid value message: type: string description: Message explaining the error list-secrets-response: required: - items type: object properties: items: type: array items: $ref: '#/components/schemas/secret-metadata' allOf: - $ref: '#/components/schemas/paginated-response' problem-details: required: - detail - title - type type: object properties: type: type: string description: A URI reference that identifies the problem type format: uri-reference default: about:blank status: maximum: 599 minimum: 400 type: integer description: HTTP status code generated by the origin server for this occurrence of the problem format: int32 example: 500 title: maxLength: 255 type: string description: Short, human-readable summary of the problem type detail: maxLength: 1024 type: string description: Human-readable explanation specific to this occurrence of the problem instance: type: string description: Reference URI that identifies the specific occurrence of the problem format: uri-reference description: An RFC 9457 problem object. externalDocs: url: https://www.rfc-editor.org/rfc/rfc9457.html x-parent: true total-count: required: - count - type type: object properties: count: minimum: 0 type: integer description: The total number of records across all pages. Might be an exact count, or a lower bound. Refer to the `type` field for the applicable semantics. format: int64 type: $ref: '#/components/schemas/total-count-type' invalid-request-problem-details: required: - errors type: object properties: errors: type: array items: $ref: '#/components/schemas/constraint-violation-error' allOf: - $ref: '#/components/schemas/problem-details' timestamp: type: integer description: Epoch timestamp in milliseconds since January 1, 1970 UTC. format: int64 example: 1752209050377 secret-metadata: required: - name type: object properties: name: $ref: '#/components/schemas/secret-name' description: type: string created_at: $ref: '#/components/schemas/timestamp' updated_at: $ref: '#/components/schemas/timestamp' update-secret-request: type: object properties: description: maxLength: 255 type: string description: The new description. Omit this field to retain the current description. value: maxLength: 4096 minLength: 1 type: string description: The new value. Omit this field to retain the current value. responses: generic-error: description: Unexpected error content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' generic-conflict-error: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 409 title: Conflict detail: The resource already exists. generic-not-found-error: description: Not found content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 404 title: Not Found detail: The requested resource could not be found. generic-unauthorized-error: description: Unauthorized content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 401 title: Unauthorized detail: Not authorized to access the requested resource. generic-forbidden-error: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' example: type: about:blank status: 403 title: Forbidden detail: Not permitted to access the requested resource. securitySchemes: apiKeyAuth: type: apiKey description: Authentication via API key. name: X-Api-Key in: header bearerAuth: type: http description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login`, `POST /api/v1/user/oidc/login`, or `POST /api/v2/oauth/token`.' scheme: bearer bearerFormat: Opaque x-refined-from: - dependency-track-openapi-v2.yaml - dependency-track-v2-openapi.yml