openapi: 3.0.0 info: description: The Eon.io REST API title: Eon accounts vaults API version: 1.0.0 servers: - url: / security: - ApiKeyAuth: [] tags: - description: Manage backup vaults that store snapshots. name: vaults x-displayName: Vaults paths: /v1/projects/{projectId}/vaults: post: description: 'Description: Creates a vault in the specified project. By default, vaults are encrypted using an Eon-managed KMS key. However, if your requirements mandate control over encryption keys, you can use a customer-managed KMS key. For more information, see [About Self-Managed Vault Keys]. If you use self-managed vault keys, you assume responsibility for securing them from unauthorized access and deletion. [About Self-Managed Vault Keys]: /user-guide/backing-up/vaults/about-self-managed-vault-keys ' operationId: createVault parameters: - description: 'ID of the project the vault is created in. You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console. ' example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d explode: false in: path name: projectId required: true schema: format: uuid type: string style: simple requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateVaultRequest' required: true responses: '201': content: application/json: schema: $ref: '#/components/schemas/CreateVaultResponse' description: Vault created. '409': content: application/json: schema: $ref: '#/components/schemas/createVault_409_response' description: A vault with the same encryption key already exists in the specified region. 1XX: description: Informational 3XX: description: Redirect 4XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Client Error 5XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Internal Server Error summary: Create Vault tags: - vaults x-internal: false x-data-access: excluded: true x-permissions: - create:vaults x-audit-log: action: create entityRefs: - entityType: vault in: resBody key: vault.id /v1/projects/{projectId}/vaults/{vaultId}: get: description: 'Description: Retrieves a vault.' operationId: getVault parameters: - description: 'ID of the project the vault is in. You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console. ' example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d explode: false in: path name: projectId required: true schema: format: uuid type: string style: simple - description: ID of the vault to retrieve. example: 36388572-9c69-5309-b362-04e7d85ae503 explode: false in: path name: vaultId required: true schema: format: uuid type: string style: simple responses: '200': content: application/json: schema: $ref: '#/components/schemas/GetVaultResponse' description: Vault retrieved. '404': description: Project or vault wasn't found. 1XX: description: Informational 3XX: description: Redirect 4XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Client Error 5XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Internal Server Error summary: Get Vault tags: - vaults x-internal: false x-data-access: excluded: true x-permissions: - read:vaults x-audit-log: excluded: true patch: description: 'Description: Updates a vault''s display name.' operationId: updateVault parameters: - description: 'ID of the project the vault is in. You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console. ' example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d explode: false in: path name: projectId required: true schema: format: uuid type: string style: simple - description: ID of the vault to update. example: 36388572-9c69-5309-b362-04e7d85ae503 explode: false in: path name: vaultId required: true schema: format: uuid type: string style: simple requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateVaultRequest' required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/UpdateVaultResponse' description: Vault is updated. '404': description: Project or vault wasn't found. 1XX: description: Informational 3XX: description: Redirect 4XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Client Error 5XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Internal Server Error summary: Update Vault tags: - vaults x-internal: false x-data-access: excluded: true x-permissions: - update:vaults x-audit-log: action: update entityRefs: - entityType: vault in: path key: vaultId /v1/projects/{projectId}/vaults/list: post: description: 'Description: Retrieves a list of vaults in the specified project.' operationId: listVaults parameters: - description: 'ID of the project whose vaults you want to retrieve. You can get your project ID from the [API Credentials](https://console.eon.io/global-management/api-credentials) page in your global management console. ' example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d explode: false in: path name: projectId required: true schema: format: uuid type: string style: simple - allowEmptyValue: true description: 'Cursor that points to the first record of the next page of results. Get this value from the previous response. To preserve the results in the same order, use the same sorting and filters in the first request as all subsequent requests. ' example: Yjk3ODZjNjktZTIwZC00NjAxLWE1MzktZjg2NGExM2IxYTZlfDE= explode: true in: query name: pageToken required: false schema: format: tobedefined type: string style: form - description: Maximum number of items to return in the response. example: 10 explode: true in: query name: pageSize required: false schema: minimum: 1 type: integer style: form responses: '200': content: application/json: schema: $ref: '#/components/schemas/ListBackupVaultResponse' description: Vaults retrieved. 1XX: description: Informational 3XX: description: Redirect 4XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Client Error 5XX: content: application/json: schema: $ref: '#/components/schemas/Error' description: Internal Server Error summary: List Vaults tags: - vaults x-mcp: true x-internal: false x-data-access: excluded: true x-permissions: - read:vaults x-audit-log: excluded: true components: schemas: GetVaultResponse: example: vault: providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 properties: vault: $ref: '#/components/schemas/BackupVault' required: - vault type: object UpdateVaultRequest: example: name: My new vault name properties: name: description: Vault display name. example: My new vault name type: string required: - name type: object Provider: description: 'Cloud provider. `PROVIDER_UNSPECIFIED` is supported only in responses. ' enum: - AWS - AZURE - GCP - MONGO_ATLAS - GOOGLE_WORKSPACE - MICROSOFT_365 - PROVIDER_UNSPECIFIED example: AWS type: string x-docs-internal-enum: - GOOGLE_WORKSPACE - MICROSOFT_365 Error: example: error: error properties: error: type: string type: object BackupVault: example: providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 properties: id: description: Vault ID. example: 37732835-d768-5990-ba93-a7c2d2e6d754 type: string vaultAccountId: description: Eon-assigned ID of the vault account. example: 1ee34dc5-0a7c-4e56-a820-917371e05c8d type: string providerAccountId: description: Cloud provider-assigned ID of the vault account. example: '123412341234' type: string name: description: Vault display name. example: AWS US East 1 type: string region: description: Region where the vault is located. example: us-east-1 type: string isManagedByEon: description: Whether the vault is in an Eon-managed vault account. example: true type: boolean vaultAttributes: $ref: '#/components/schemas/VaultProviderAttributes' required: - id - isManagedByEon - name - providerAccountId - region - vaultAccountId - vaultAttributes type: object VaultProviderAttributesInput: description: 'Cloud-provider-specific vault attributes. ' example: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 properties: cloudProvider: $ref: '#/components/schemas/Provider' aws: $ref: '#/components/schemas/AwsVaultConfigInput' required: - cloudProvider type: object AwsVaultConfigInput: description: 'AWS-specific vault configuration. ' example: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 nullable: true properties: encryptionKey: description: 'ARN of the KMS key used for encryption. Omitted if the key is managed by Eon. ' example: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 type: string type: object ListBackupVaultResponse: example: nextToken: Y2NiMGYyZmMtYjYyZi00OTc5LTgzNjQtYmQ2YjEyYzdjZTNifDE= vaults: - providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 - providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 totalCount: 188 properties: vaults: items: $ref: '#/components/schemas/BackupVault' type: array nextToken: description: 'Cursor that points to the first record of the next page of results. Pass this value in the next request. ' example: Y2NiMGYyZmMtYjYyZi00OTc5LTgzNjQtYmQ2YjEyYzdjZTNifDE= type: string totalCount: description: Total number of restore jobs that matched the filter options. example: 188 type: integer required: - totalCount - vaults type: object createVault_409_response: example: error: error properties: error: type: string type: object AwsVaultConfig: description: 'AWS-specific vault configuration. ' example: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 nullable: true properties: encryptionKey: description: 'ARN of the KMS key used for encryption. Omitted if the key is managed by Eon. ' example: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 type: string type: object UpdateVaultResponse: example: vault: providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 properties: vault: $ref: '#/components/schemas/BackupVault' required: - vault type: object VaultProviderAttributes: description: 'Cloud-provider-specific vault attributes. ' example: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 properties: cloudProvider: $ref: '#/components/schemas/Provider' aws: $ref: '#/components/schemas/AwsVaultConfig' required: - cloudProvider type: object CreateVaultResponse: example: vault: providerAccountId: '123412341234' name: AWS US East 1 vaultAccountId: 1ee34dc5-0a7c-4e56-a820-917371e05c8d vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 id: 37732835-d768-5990-ba93-a7c2d2e6d754 isManagedByEon: true region: us-east-1 properties: vault: $ref: '#/components/schemas/BackupVault' required: - vault type: object CreateVaultRequest: example: name: EU central vaultAttributes: cloudProvider: AWS aws: encryptionKey: arn:aws:kms:us-east-1:123456789012:key/4692190d-ae52-56fe-9937-6aa2c4e3df62 region: eu-central-1 properties: name: description: Vault display name. example: EU central type: string region: description: Region where the vault is hosted. example: eu-central-1 type: string vaultAttributes: $ref: '#/components/schemas/VaultProviderAttributesInput' required: - name - region - vaultAttributes type: object securitySchemes: ApiKeyAuth: bearerFormat: JWT scheme: bearer type: http