openapi: 3.0.1 info: title: Very Good Security (VGS) aliases organizations API description: Specification of the public Very Good Security (VGS) APIs. Covers the VGS Vault HTTP API for tokenization (create / reveal / update / delete aliases) served from the verygoodvault.com hosts with HTTP Basic authentication, and the VGS Accounts (control plane) API for managing organizations, vaults, and routes served from accounts.apps.verygoodsecurity.com with a Bearer access token obtained via the OAuth2 client-credentials flow. Endpoint shapes for the Vault API mirror the published VGS Vault API reference; Accounts resources are modeled from VGS platform / IAM documentation. termsOfService: https://www.verygoodsecurity.com/terms contact: name: VGS Support email: support@verygoodsecurity.com version: '1.0' servers: - url: https://api.sandbox.verygoodvault.com description: Vault API - Sandbox - url: https://api.live.verygoodvault.com description: Vault API - Live - url: https://api.live-eu-1.verygoodvault.com description: Vault API - Live EU - url: https://accounts.apps.verygoodsecurity.com description: Accounts (control plane) API tags: - name: organizations description: Organization resources on the VGS Accounts API. paths: /organizations: get: operationId: listOrganizations tags: - organizations summary: List organizations description: Reads basic organization details accessible to the authenticated service account (requires the organizations:read scope). Served from the VGS Accounts control plane. security: - bearerAuth: [] responses: '200': description: OK content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Organization' default: $ref: '#/components/responses/ApiErrorsResponse' /organizations/{organizationId}: parameters: - $ref: '#/components/parameters/organizationId' get: operationId: getOrganization tags: - organizations summary: Get organization description: Retrieves a single organization by identifier (organizations:read scope). security: - bearerAuth: [] responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/Organization' default: $ref: '#/components/responses/ApiErrorsResponse' components: responses: ApiErrorsResponse: description: Something went wrong content: application/json: schema: type: object properties: errors: type: array minItems: 1 items: $ref: '#/components/schemas/ApiError' parameters: organizationId: name: organizationId in: path required: true description: Organization identifier. schema: type: string schemas: Organization: type: object properties: id: type: string description: Organization identifier. name: type: string description: Organization name. type: type: string description: Resource type. example: organizations ApiError: type: object properties: status: type: integer description: HTTP status code. title: type: string description: High-level reason of why the request failed. detail: type: string description: Explanation of what exactly went wrong. href: type: string description: Request URL. securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication used by the VGS Vault HTTP API. Username and password are the vault access credentials generated in the VGS dashboard. bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Bearer access token used by the VGS Accounts API. Obtain the token from the OAuth2 client-credentials endpoint at https://auth.verygoodsecurity.com/auth/realms/vgs/protocol/openid-connect/token using a service-account client id and secret, then pass it as Authorization: Bearer .'