Vault object
Create, get, list, and archive endpoints return this structure.
| フィールド | 型 | 説明 |
|---|
id | string | Vault ID with the vault_ prefix |
type | string | Always "vault" |
display_name | string | Vault display name, at most 255 characters |
metadata | object | Custom metadata stored with the Vault; defaults to {} when omitted. created_by is reserved by Forward and must not be supplied by callers |
archived_at | string | null | Archive time in RFC 3339 format; null while active |
created_at | string | Creation time in RFC 3339 format |
updated_at | string | Last update time in RFC 3339 format |
identity_id | string | null | Owning Forward identity. Returns the Identity ID for an Identity-owned resource, or null otherwise. See Identity ownership. |
icon_url | string | null | Icon URL associated by Forward |
binding_info | Binding info | Binding information, such as Template reference counts |
Credentials in a Vault are managed through the separate Forward Credential API and are not embedded in Vault responses.
Identity の帰属
アカウント(または Workspace)には複数の Identity を作成できます。各 Identity は、そのアカウント(または Workspace)と連携する製品のエンドユーザーを表します。
Vault はアカウント(または Workspace)または特定の Identity に帰属できます。帰属によって、リソースを参照・操作できる範囲が決まります。
帰属の指定
| Caller | Owner | How to select |
|---|
| PAT | Account / Workspace | Omit identity_id (the default, unchanged behavior). |
| PAT | A specific Identity | Pass the query parameter identity_id=<identity_id>. |
| Admin SAT | Workspace | Resolved automatically; parameters cannot switch ownership. |
| Identity-bound SAT | The bound Identity | Resolved automatically; parameters cannot switch ownership. |
identity_id は Identity に属するリソースを操作する場合のみ使用する任意のパラメーターです。PAT では明示的に指定でき、省略時は管理者スコープになります。SAT では Identity スコープのトークンを発行し、空値を含め、このパラメーターを明示的に指定しないでください。指定すると HTTP 400 が返されます。
PAT で指定する Identity は、その PAT が表すアカウントまたは Workspace に属し、有効である必要があります。存在しない、無効化済み、削除済み、または呼び出し元に属さない場合は 404 が返されます。
帰属の分離
- アカウントまたは Workspace のスコープからは、Identity に属する Vault を参照できません。
- Identity は、アカウント(または Workspace)自体や同じアカウント内の他の Identity に属する Vault を参照できません。
- 有効な Identity スコープ(有効な
identity_id を指定した PAT または Identity SAT)では、別スコープのリソースに対する ID 指定の取得、更新、アーカイブ、削除はすべて 404 を返します。リソースが存在しない場合と、他の所有者に属する場合を区別しません。
identity_id を指定しない PAT と Admin SAT は従来どおり、Owner mismatch に対して 403 を返します。
対応するエンドポイント
Vault の作成、検索、一覧取得、取得、更新、アーカイブ、削除は identity_id クエリパラメーターに対応しています。
Vault credentials inherit ownership entirely from their Vault. See Credential identity ownership.
GET /api/v1/forward/resources/batch は、現時点では identity_id に対応していません。参照範囲のルールは従来どおりです。
Binding info
Reference summary included by Forward in Vault responses.
| フィールド | 型 | 説明 |
|---|
agent_template_count | integer | Number of Templates currently bound to the Vault |
| フィールド | 型 | 説明 |
|---|
data | array of Vault objects | Records on the current page |
has_more | boolean | Whether another page is available |
next_page | string | null | Forward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null |
first_id | string | null | ID of the first record on the current page |
last_id | string | null | ID of the last record on the current page |
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.