Skip to main content
Vaults

Vault Schemas

Forward API reference.

Vault object

Create, get, list, and archive endpoints return this structure.
FieldTypeDescription
idstringVault ID with the vault_ prefix
typestringAlways "vault"
display_namestringVault display name, at most 255 characters
metadataobjectCustom metadata stored with the Vault; defaults to {} when omitted. created_by is reserved by Forward and must not be supplied by callers
archived_atstring | nullArchive time in RFC 3339 format; null while active
created_atstringCreation time in RFC 3339 format
updated_atstringLast update time in RFC 3339 format
identity_idstring | nullOwning Forward identity. Returns the Identity ID for an Identity-owned resource, or null otherwise. See Identity ownership.
icon_urlstring | nullIcon URL associated by Forward
binding_infoBinding infoBinding information, such as Template reference counts
Credentials in a Vault are managed through the separate Forward Credential API and are not embedded in Vault responses.

Identity ownership

An account (or Workspace) can have multiple Identities. Each Identity represents an end user of the product integrated with that account (or Workspace). A Vault can belong to the account (or Workspace) or to an Identity. Ownership determines who can see and operate it.

Selecting ownership

CallerOwnerHow to select
PATAccount / WorkspaceOmit identity_id (the default, unchanged behavior).
PATA specific IdentityPass the query parameter identity_id=<identity_id>.
Admin SATWorkspaceResolved automatically; parameters cannot switch ownership.
Identity-bound SATThe bound IdentityResolved automatically; parameters cannot switch ownership.
identity_id is optional and is used only for Identity-owned resources. A PAT can specify it explicitly; omitting it uses the administrator scope. With SAT, issue an Identity-scoped token and do not explicitly pass this parameter, even with an empty value. Doing so returns HTTP 400. An Identity specified with a PAT must belong to the account or Workspace represented by that PAT and must be enabled. A nonexistent, disabled, deleted, or foreign Identity returns 404.

Ownership isolation

  • Calls in the account or Workspace scope cannot see Identity-owned Vaults.
  • An Identity cannot see Vaults owned by the account (or Workspace) itself or by other Identities in the same account.
  • In a valid Identity scope (a PAT with a valid identity_id, or an Identity SAT), cross-scope get-by-ID, update, archive, and delete operations return 404, without distinguishing a nonexistent resource from a resource owned by someone else.
  • PAT calls without identity_id and Admin SAT calls retain the existing behavior: an Owner mismatch returns 403.

Supported endpoints

Create, search, list, get, update, archive, and delete Vault endpoints support the identity_id query parameter. Vault credentials inherit ownership entirely from their Vault. See Credential identity ownership.
GET /api/v1/forward/resources/batch does not yet support identity_id. Its visibility rules are unchanged.

Binding info

Reference summary included by Forward in Vault responses.
FieldTypeDescription
agent_template_countintegerNumber of Templates currently bound to the Vault

List pagination fields

FieldTypeDescription
dataarray of Vault objectsRecords on the current page
has_morebooleanWhether another page is available
next_pagestring | nullForward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null
first_idstring | nullID of the first record on the current page
last_idstring | nullID of the last record on the current page
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.
Best Practices
API reference