Skip to main content
Vaults

Vault スキーマ

Forward API リファレンス。

Vault object

Create, get, list, and archive endpoints return this structure.
フィールド型説明
idstringVault ID with the vault_ prefix
typestringAlways "vault"
display_namestringVault display name, at most 255 characters
metadataobjectCustom metadata stored with the Vault; defaults to {} when omitted. created_by is reserved by Forward and must not be supplied by callers
archived_atstring | nullArchive time in RFC 3339 format; null while active
created_atstringCreation time in RFC 3339 format
updated_atstringLast update time in RFC 3339 format
identity_idstring | nullOwning Forward identity. Returns the Identity ID for an Identity-owned resource, or null otherwise. See Identity ownership.
icon_urlstring | nullIcon URL associated by Forward
binding_infoBinding infoBinding information, such as Template reference counts
Credentials in a Vault are managed through the separate Forward Credential API and are not embedded in Vault responses.

Identity の帰属

アカウント(または Workspace)には複数の Identity を作成できます。各 Identity は、そのアカウント(または Workspace)と連携する製品のエンドユーザーを表します。 Vault はアカウント(または Workspace)または特定の Identity に帰属できます。帰属によって、リソースを参照・操作できる範囲が決まります。

帰属の指定

CallerOwnerHow to select
PATAccount / WorkspaceOmit identity_id (the default, unchanged behavior).
PATA specific IdentityPass the query parameter identity_id=<identity_id>.
Admin SATWorkspaceResolved automatically; parameters cannot switch ownership.
Identity-bound SATThe bound IdentityResolved automatically; parameters cannot switch ownership.
identity_id は Identity に属するリソースを操作する場合のみ使用する任意のパラメーターです。PAT では明示的に指定でき、省略時は管理者スコープになります。SAT では Identity スコープのトークンを発行し、空値を含め、このパラメーターを明示的に指定しないでください。指定すると HTTP 400 が返されます。 PAT で指定する Identity は、その PAT が表すアカウントまたは Workspace に属し、有効である必要があります。存在しない、無効化済み、削除済み、または呼び出し元に属さない場合は 404 が返されます。

帰属の分離

  • アカウントまたは Workspace のスコープからは、Identity に属する Vault を参照できません。
  • Identity は、アカウント(または Workspace)自体や同じアカウント内の他の Identity に属する Vault を参照できません。
  • 有効な Identity スコープ(有効な identity_id を指定した PAT または Identity SAT)では、別スコープのリソースに対する ID 指定の取得、更新、アーカイブ、削除はすべて 404 を返します。リソースが存在しない場合と、他の所有者に属する場合を区別しません。
  • identity_id を指定しない PAT と Admin SAT は従来どおり、Owner mismatch に対して 403 を返します。

対応するエンドポイント

Vault の作成、検索、一覧取得、取得、更新、アーカイブ、削除は identity_id クエリパラメーターに対応しています。 Vault credentials inherit ownership entirely from their Vault. See Credential identity ownership.
GET /api/v1/forward/resources/batch は、現時点では identity_id に対応していません。参照範囲のルールは従来どおりです。

Binding info

Reference summary included by Forward in Vault responses.
フィールド型説明
agent_template_countintegerNumber of Templates currently bound to the Vault

List pagination fields

フィールド型説明
dataarray of Vault objectsRecords on the current page
has_morebooleanWhether another page is available
next_pagestring | nullForward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null
first_idstring | nullID of the first record on the current page
last_idstring | nullID of the last record on the current page
The request cursor parameters page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.