openapi: 3.0.1 info: title: Very Good Security (VGS) aliases routes API description: Specification of the public Very Good Security (VGS) APIs. Covers the VGS Vault HTTP API for tokenization (create / reveal / update / delete aliases) served from the verygoodvault.com hosts with HTTP Basic authentication, and the VGS Accounts (control plane) API for managing organizations, vaults, and routes served from accounts.apps.verygoodsecurity.com with a Bearer access token obtained via the OAuth2 client-credentials flow. Endpoint shapes for the Vault API mirror the published VGS Vault API reference; Accounts resources are modeled from VGS platform / IAM documentation. termsOfService: https://www.verygoodsecurity.com/terms contact: name: VGS Support email: support@verygoodsecurity.com version: '1.0' servers: - url: https://api.sandbox.verygoodvault.com description: Vault API - Sandbox - url: https://api.live.verygoodvault.com description: Vault API - Live - url: https://api.live-eu-1.verygoodvault.com description: Vault API - Live EU - url: https://accounts.apps.verygoodsecurity.com description: Accounts (control plane) API tags: - name: routes description: Inbound / outbound proxy route resources on the VGS Accounts API. paths: /vaults/{vaultId}/routes: parameters: - $ref: '#/components/parameters/vaultId' get: operationId: listRoutes tags: - routes summary: List routes description: Lists inbound and outbound proxy routes configured on the vault (requires the routes:read scope). security: - bearerAuth: [] responses: '200': description: OK content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Route' default: $ref: '#/components/responses/ApiErrorsResponse' post: operationId: createRoute tags: - routes summary: Create route description: Creates an inbound (reverse) or outbound (forward) proxy route on the vault that redacts or reveals sensitive data in transit (requires the routes:write scope). security: - bearerAuth: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Route' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/Route' default: $ref: '#/components/responses/ApiErrorsResponse' /vaults/{vaultId}/routes/{routeId}: parameters: - $ref: '#/components/parameters/vaultId' - $ref: '#/components/parameters/routeId' get: operationId: getRoute tags: - routes summary: Get route description: Retrieves a single route by identifier (routes:read scope). security: - bearerAuth: [] responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/Route' default: $ref: '#/components/responses/ApiErrorsResponse' put: operationId: updateRoute tags: - routes summary: Update route description: Replaces a route configuration on the vault (routes:write scope). security: - bearerAuth: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Route' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/Route' default: $ref: '#/components/responses/ApiErrorsResponse' delete: operationId: deleteRoute tags: - routes summary: Delete route description: Removes a route from the vault (routes:write scope). security: - bearerAuth: [] responses: '204': description: No Content default: $ref: '#/components/responses/ApiErrorsResponse' components: parameters: routeId: name: routeId in: path required: true description: Route identifier. schema: type: string vaultId: name: vaultId in: path required: true description: Vault identifier. schema: type: string example: tntabcdefg schemas: Route: type: object properties: id: type: string description: Route identifier. type: type: string enum: - INBOUND - OUTBOUND description: INBOUND (reverse) proxy routes sit between clients and your server; OUTBOUND (forward) proxy routes sit between your server and third parties. protocol: type: string enum: - HTTP description: Proxy protocol. host_endpoint: type: string description: Upstream host pattern the route applies to. tags: type: object additionalProperties: type: string description: Arbitrary tags applied to the route. ApiError: type: object properties: status: type: integer description: HTTP status code. title: type: string description: High-level reason of why the request failed. detail: type: string description: Explanation of what exactly went wrong. href: type: string description: Request URL. responses: ApiErrorsResponse: description: Something went wrong content: application/json: schema: type: object properties: errors: type: array minItems: 1 items: $ref: '#/components/schemas/ApiError' securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication used by the VGS Vault HTTP API. Username and password are the vault access credentials generated in the VGS dashboard. bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Bearer access token used by the VGS Accounts API. Obtain the token from the OAuth2 client-credentials endpoint at https://auth.verygoodsecurity.com/auth/realms/vgs/protocol/openid-connect/token using a service-account client id and secret, then pass it as Authorization: Bearer .'