# Google Vault API > Google Vault is the information-governance and eDiscovery service for Google Workspace. Its > REST API (vault.googleapis.com, v1) lets an administrator open matters, place and lift legal > holds, save search queries, count what a search would return, and export matching data from > Gmail, Drive, Groups, Chat, Voice, Calendar and Gemini. Access is OAuth 2.0 only and requires > Google Workspace Vault privileges. Generated by API Evangelist (apievangelist.com) on 2026-09-12 from Google's published Discovery document (vault:v1, revision 20260905) and its public documentation. This is a third-party profile; it is not published by Google. ## Contract - [Discovery document (first-party, verbatim)](https://vault.googleapis.com/$discovery/rest?version=v1): Google's own machine-readable contract — 33 methods, 71 schemas, revision 20260905. - [REST reference](https://developers.google.com/workspace/vault/reference/rest): the human reference for the same surface. - Base URL: https://vault.googleapis.com — all paths under /v1. - Google publishes no OpenAPI for Vault. The OpenAPI documents in this repo are derived from the Discovery document, one per resource family. ## Authentication - [Choose scopes](https://developers.google.com/workspace/vault/auth): exactly two scopes, https://www.googleapis.com/auth/ediscovery (all 33 methods) and https://www.googleapis.com/auth/ediscovery.readonly (11 read methods). - [Authorization overview](https://developers.google.com/workspace/guides/auth-overview) - [Troubleshoot authentication](https://developers.google.com/workspace/vault/troubleshoot-authentication-authorization) - OAuth 2.0 bearer tokens only. No API keys, no anonymous access. Server-to-server access uses a service account with domain-wide delegation impersonating a user who holds Vault privileges. ## Guides - [Manage matters](https://developers.google.com/workspace/vault/guides/matters) - [Manage holds](https://developers.google.com/workspace/vault/guides/holds) - [Manage saved queries](https://developers.google.com/workspace/vault/guides/saved-queries) - [Manage exports](https://developers.google.com/workspace/vault/guides/exports) - [Count query results](https://developers.google.com/workspace/vault/guides/count) - [Python quickstart](https://developers.google.com/workspace/vault/quickstart/python) - [Java quickstart](https://developers.google.com/workspace/vault/quickstart/java) ## Operating limits - [Usage limits](https://developers.google.com/workspace/vault/limits): per-minute per-project quotas (matter reads 120, hold reads 228, LRO reads 300, matter writes 60, hold writes 60, export writes 20, saved query writes 45, matter permission writes 30, search counts 20), a 600/minute organization-wide matter-read ceiling shared with the Vault web UI, and a hard product limit of 20 concurrent exports per organization. - matters.list costs TEN matter reads per call. Poll it carefully. - No rate-limit response headers are published. The only runtime signal is HTTP 429; retry with truncated exponential backoff. - [Handle errors](https://developers.google.com/workspace/vault/guides/errors): 400, 401, 404, 409, 429, 500, in the Google google.rpc.Status envelope — not RFC 9457 problem+json. ## What an agent must know before writing - There is NO idempotency key anywhere on this API. A retried create can create a second object. Check by listing the parent before retrying. - Deleting a matter is reversible: only a closed matter can be deleted, it stays restorable with matters.undelete for approximately 30 days, then it is permanently purged. - Closing a matter is reversible with matters.reopen. Adding permissions or held accounts is reversible with the matching remove call. - Deleting a HOLD is NOT reversible. No restore method exists, and lifting a hold returns the data it was preserving to normal retention. Treat it as a legal act. - There is no sandbox, no test mode and no dry-run flag. Every call hits production data. matters.count is the only rehearsal: it sizes a search without creating a hold or an export. - Exports are asynchronous — poll matters.exports.get until status leaves IN_PROGRESS — and each in-flight export occupies one of the organization's 20 slots. ## Agent surfaces - No MCP server. Google ships official remote MCP servers for eight Workspace products (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat, People) and Vault is not one of them. - No A2A agent card on any Google host probed. - No webhooks, no events, no AsyncAPI — the Vault API has no watch or push-notification method. ## Client libraries - npm [@googleapis/vault](https://www.npmjs.com/package/@googleapis/vault) and [googleapis](https://www.npmjs.com/package/googleapis) - PyPI [google-api-python-client](https://pypi.org/project/google-api-python-client/) - Maven [com.google.apis:google-api-services-vault](https://central.sonatype.com/artifact/com.google.apis/google-api-services-vault) - Go [google.golang.org/api/vault/v1](https://pkg.go.dev/google.golang.org/api/vault/v1) - RubyGems [google-apis-vault_v1](https://rubygems.org/gems/google-apis-vault_v1) - NuGet [Google.Apis.Vault.v1](https://www.nuget.org/packages/Google.Apis.Vault.v1) - Packagist [google/apiclient](https://packagist.org/packages/google/apiclient) ## Operations and support - [Release notes](https://developers.google.com/workspace/vault/release-notes): three dated entries in total, the newest from 2020-06-01. The Discovery document is still regenerated regularly, so diff the revision field rather than watching this page. - [Google Workspace Status Dashboard](https://www.google.com/appsstatus/dashboard/) — Vault is listed. - [Developer support](https://developers.google.com/workspace/vault/support) - [Vault help centre](https://knowledge.workspace.google.com/vault) ## Commercial - The Vault API is available at no additional cost to Google Workspace customers; there are no API plans or metering. - Vault is included with Frontline Standard/Plus, Business Plus, Enterprise Standard/Plus, all Education editions, Enterprise Essentials and Essentials Plus (domain-verified) and legacy G Suite Business. Other editions buy a Vault add-on license. - [Workspace pricing](https://workspace.google.com/pricing.html) · [Terms](https://developers.google.com/terms) · [Privacy](https://policies.google.com/privacy)