Skip to main content
Vaults

Search Vaults

Search Vaults visible in the current Owner Scope using Forward API filters.

POST /api/v1/forward/vaults/search Supports PAT, Admin SAT, and Identity SAT. You must include x-qoder-beta: search-2026-08-31. Search filters are optional and belong in the JSON body; search parameters in the URL query are ignored. The request body must be a single JSON object; use {} for no filters.

Query parameters

ParameterTypeRequiredDescription
identity_idstringNoOptional; used only for Identity-owned resources. PAT callers can pass it explicitly; omitting it uses the administrator scope. For SAT, issue an Identity-scoped token and do not explicitly pass this parameter, or the request returns HTTP 400. See Identity ownership.
Without identity_id, a PAT searches Vaults owned by the current account or Workspace. With it, a PAT searches only the specified Identity. Admin SAT searches only the Workspace; Identity SAT searches only the token-bound Identity. Resources in other scopes are excluded.

Request body

ParameterTypeDescription
metadataobject<string,string>Exact metadata filters combined with AND. Maximum 16 entries.
limitintegerPage size. Default: 20. Range: 1–100.
pagestringCursor returned in next_page from the previous response.
include_archivedbooleanWhether to include archived Vaults visible to both CAS and Forward. Default: false.
namestringCase-insensitive substring match on the display name. Maximum length: 255.
curl -X POST "https://api.qoder.com/api/v1/forward/vaults/search" \
  -H "Authorization: Bearer $QODER_PAT" \
  -H "Content-Type: application/json" \
  -H "x-qoder-beta: search-2026-08-31" \
  -d '{"metadata":{"team":"core"},"name":"production","limit":20}'

Response

FieldTypeDescription
dataarrayForward-visible resources on the current page. Resource fields match the corresponding List endpoint.
first_idstring | nullID of the first resource on the current page.
last_idstring | nullID of the last resource on the current page.
has_morebooleanWhether a subsequent page of Forward-visible resources is confirmed to exist.
next_pagestring | nullCursor for the next page, or null when there is no next page.
{
  "data": [],
  "first_id": null,
  "has_more": false,
  "last_id": null,
  "next_page": null
}
Fields in data match List Vaults. Metadata keys must contain 1–64 characters and cannot consist only of whitespace. Metadata values must be strings with a maximum length of 512 characters. Clients must replay next_page exactly as returned and must not construct cursors.

Errors

HTTPTypeTrigger
400invalid_request_errorThe Beta header or request body is missing, or a search parameter is invalid. Also returned if SAT explicitly includes identity_id.
401authentication_errorThe authentication token is missing or invalid.
403permission_errorThe caller cannot access the resource.
404not_found_errorThe PAT-specified identity_id does not exist, is disabled, deleted, or does not belong to the caller.
429rate_limit_errorA Forward or downstream rate limit is exceeded.
500/502/503api_errorForward or a dependent service failed.
Best Practices
API reference