/create-rotated-secret

Body Params
string
string

API ID to rotate (relevant only for rotator-type=api-key)

string

API key to rotate (relevant only for rotator-type=api-key)

string

ApplicationId (used in azure)

string
Defaults to use-user-creds

The credentials to connect with use-user-creds/use-target-creds

string

Whether to automatically rotate every --rotation-interval days, or disable existing automatic rotation [true/false]

string
Defaults to us-east-2

Aws Region (relevant only for aws)

string

Secret payload to be sent with rotation request (relevant only for rotator-type=custom)

string

Protection from accidental deletion of this object [true/false]

string

Description of the object

string

Base64-encoded service account private key text

string

The email of the gcp service account to rotate

string

The key id of the gcp service account to rotate

string

Create a new access key without deleting the old key from AWS for backup (relevant only for AWS) [true/false]

string

Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret

boolean
Defaults to false

Set output format to JSON

string

The name of a key that used to encrypt the secret value (if empty, the account default protectionKey key will be used)

string

Lock this secret for read/update while an SRA session is active

string

Deprecated - use description

string
required

Secret name

string

The length of the password to be generated

string

StringOrBool accepts JSON strings, booleans, and numbers for backward compatibility with older SDK versions that send boolean values for rotate-after-disconnect.

string

rotated-username password (relevant only for rotator-type=password)

string

username to be rotated, if selected use-self-creds at rotator-creds-type, this username will try to rotate it's own password, if use-target-creds is selected, target credentials will be use to rotate the rotated-password (relevant only for rotator-type=password)

int32

The Hour of the rotation in UTC. Default rotation-hour is 14:00

string

The number of days to wait between every automatic key rotation (1-365)

string
string

Custom rotation command (relevant only for ssh target)

string
required

Rotator Type

string

Rotate same password for each host from the Linked Target (relevant only for Linked Target)

boolean
Defaults to false

Allow providing external user for a domain users (relevant only for rdp)

string

The AWS account id (relevant only for aws)

boolean

The AWS native cli

string

Deprecated. use secure-access-certificate-issuer

string

Path to the SSH Certificate Issuer for your Akeyless Secure Access

string

The DB name (relevant only for DB Dynamic-Secret)

string

The db schema (relevant only for mssql or postgresql)

boolean

Enable this flag to prevent simultaneous use of the same secret

string

Enable/Disable secure remote access [true/false]

secure-access-host
array of strings

Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)

secure-access-host
string

Required when the Dynamic Secret is used for a domain user (relevant only for RDP Dynamic-Secret)

string

Override the RDP Domain username (relevant only for rdp)

string

Destination URL to inject secrets

boolean
Defaults to false

Enable Web Secure Remote Access

boolean
Defaults to false

Secure browser viaAkeyless's Secure Remote Access (SRA) (relevant only for aws or azure)

boolean
Defaults to false

Web-Proxy via Akeyless's Secure Remote Access (SRA) (relevant only for aws or azure)

string

Deprecated: use RotatedPassword

string

Deprecated: use RotatedUser

string

The name of the storage account key to rotate [key1/key2/kerb1/kerb2] (relevat to azure-storage-account)

tags
array of strings

Add tags attached to this object

tags
target
array of strings

A list of linked targets to be associated, Relevant only for Secure Remote Access for ssh cert issuer, ldap rotated secret and ldap dynamic secret, To specify multiple targets use argument multiple times

target
string
required

Target name

string

Authentication token (see /auth and /configure)

string

The universal identity token, Required only for universal_identity authentication

string
Defaults to cn

LDAP User Attribute, Default value "cn"

string

LDAP User Base DN

Responses

Language
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
Footer Section