curl --request POST \
--url https://your-syteca-host/SytecaACB/api/secrets \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"parent_folder_id": 1,
"parent_folder_name": "<string>",
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": [
"<string>"
],
"record_activities": true,
"permissions": {
"inherit_users_and_roles": false,
"inherit_features": false,
"users": [
{
"name": "<string>",
"features": []
}
],
"user_groups": [
{
"name": "<string>",
"features": []
}
]
}
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/secrets"
payload = {
"name": "<string>",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"parent_folder_id": 1,
"parent_folder_name": "<string>",
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": ["<string>"],
"record_activities": True,
"permissions": {
"inherit_users_and_roles": False,
"inherit_features": False,
"users": [
{
"name": "<string>",
"features": []
}
],
"user_groups": [
{
"name": "<string>",
"features": []
}
]
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
login: '<string>',
description: '<string>',
password: '<string>',
parent_folder_id: 1,
parent_folder_name: '<string>',
domain: '<string>',
computer_name: '<string>',
url: '<string>',
server: '<string>',
computers: ['<string>'],
record_activities: true,
permissions: {
inherit_users_and_roles: false,
inherit_features: false,
users: [{name: '<string>', features: []}],
user_groups: [{name: '<string>', features: []}]
}
})
};
fetch('https://your-syteca-host/SytecaACB/api/secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/secrets",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'login' => '<string>',
'description' => '<string>',
'password' => '<string>',
'parent_folder_id' => 1,
'parent_folder_name' => '<string>',
'domain' => '<string>',
'computer_name' => '<string>',
'url' => '<string>',
'server' => '<string>',
'computers' => [
'<string>'
],
'record_activities' => true,
'permissions' => [
'inherit_users_and_roles' => false,
'inherit_features' => false,
'users' => [
[
'name' => '<string>',
'features' => [
]
]
],
'user_groups' => [
[
'name' => '<string>',
'features' => [
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/secrets"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/api/secrets")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/secrets")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"id": 123,
"name": "<string>",
"type": "None",
"login": "<string>",
"description": "<string>",
"parent_folder_id": 123,
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": [
"<string>"
],
"file_transfer": {
"protocol": "Sftp",
"port": 22
},
"rotation": {
"enabled": true,
"rotate_every_min": 2
},
"record_activities": true,
"check_out": {
"enabled": true,
"rotate_on_checkin": true,
"auto_checkin_after_min": 60
},
"require_approval": {
"require_approval_type": "None",
"approver_users": [
"<string>"
],
"approver_user_groups": [
"<string>"
],
"require_owners_and_approvers": false,
"working_dates": {
"from": "2023-11-07T05:31:56Z",
"to": "2023-11-07T05:31:56Z"
},
"working_hours": {
"from": "<string>",
"to": "<string>"
},
"working_days": [
"Sunday"
]
},
"permissions": {
"inherit_users_and_roles": false,
"inherit_features": false,
"users": [
{
"name": "<string>",
"access_type": "None",
"features": [
"CopyPassword"
]
}
],
"user_groups": [
{
"name": "<string>",
"access_type": "None",
"features": [
"CopyPassword"
]
}
]
},
"check_password": {
"enabled": false,
"check_every": 30,
"check_period_type": "Minute"
},
"check_password_status": "None",
"last_password_check_utc": "2023-11-07T05:31:56Z",
"password_rotation_status": "Disabled",
"last_password_rotation_utc": "2023-11-07T05:31:56Z"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Add Secret
Syteca ACB REST API endpoint to create a new secret — Windows / AD / Unix SSH / Unix Telnet / Web / MSSQL account. Required vs ignored fields depend on the secret’s type.
curl --request POST \
--url https://your-syteca-host/SytecaACB/api/secrets \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "<string>",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"parent_folder_id": 1,
"parent_folder_name": "<string>",
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": [
"<string>"
],
"record_activities": true,
"permissions": {
"inherit_users_and_roles": false,
"inherit_features": false,
"users": [
{
"name": "<string>",
"features": []
}
],
"user_groups": [
{
"name": "<string>",
"features": []
}
]
}
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/secrets"
payload = {
"name": "<string>",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"parent_folder_id": 1,
"parent_folder_name": "<string>",
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": ["<string>"],
"record_activities": True,
"permissions": {
"inherit_users_and_roles": False,
"inherit_features": False,
"users": [
{
"name": "<string>",
"features": []
}
],
"user_groups": [
{
"name": "<string>",
"features": []
}
]
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
login: '<string>',
description: '<string>',
password: '<string>',
parent_folder_id: 1,
parent_folder_name: '<string>',
domain: '<string>',
computer_name: '<string>',
url: '<string>',
server: '<string>',
computers: ['<string>'],
record_activities: true,
permissions: {
inherit_users_and_roles: false,
inherit_features: false,
users: [{name: '<string>', features: []}],
user_groups: [{name: '<string>', features: []}]
}
})
};
fetch('https://your-syteca-host/SytecaACB/api/secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/secrets",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'login' => '<string>',
'description' => '<string>',
'password' => '<string>',
'parent_folder_id' => 1,
'parent_folder_name' => '<string>',
'domain' => '<string>',
'computer_name' => '<string>',
'url' => '<string>',
'server' => '<string>',
'computers' => [
'<string>'
],
'record_activities' => true,
'permissions' => [
'inherit_users_and_roles' => false,
'inherit_features' => false,
'users' => [
[
'name' => '<string>',
'features' => [
]
]
],
'user_groups' => [
[
'name' => '<string>',
'features' => [
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/secrets"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/api/secrets")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/secrets")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"login\": \"<string>\",\n \"description\": \"<string>\",\n \"password\": \"<string>\",\n \"parent_folder_id\": 1,\n \"parent_folder_name\": \"<string>\",\n \"domain\": \"<string>\",\n \"computer_name\": \"<string>\",\n \"url\": \"<string>\",\n \"server\": \"<string>\",\n \"computers\": [\n \"<string>\"\n ],\n \"record_activities\": true,\n \"permissions\": {\n \"inherit_users_and_roles\": false,\n \"inherit_features\": false,\n \"users\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ],\n \"user_groups\": [\n {\n \"name\": \"<string>\",\n \"features\": []\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"id": 123,
"name": "<string>",
"type": "None",
"login": "<string>",
"description": "<string>",
"parent_folder_id": 123,
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>",
"computers": [
"<string>"
],
"file_transfer": {
"protocol": "Sftp",
"port": 22
},
"rotation": {
"enabled": true,
"rotate_every_min": 2
},
"record_activities": true,
"check_out": {
"enabled": true,
"rotate_on_checkin": true,
"auto_checkin_after_min": 60
},
"require_approval": {
"require_approval_type": "None",
"approver_users": [
"<string>"
],
"approver_user_groups": [
"<string>"
],
"require_owners_and_approvers": false,
"working_dates": {
"from": "2023-11-07T05:31:56Z",
"to": "2023-11-07T05:31:56Z"
},
"working_hours": {
"from": "<string>",
"to": "<string>"
},
"working_days": [
"Sunday"
]
},
"permissions": {
"inherit_users_and_roles": false,
"inherit_features": false,
"users": [
{
"name": "<string>",
"access_type": "None",
"features": [
"CopyPassword"
]
}
],
"user_groups": [
{
"name": "<string>",
"access_type": "None",
"features": [
"CopyPassword"
]
}
]
},
"check_password": {
"enabled": false,
"check_every": 30,
"check_period_type": "Minute"
},
"check_password_status": "None",
"last_password_check_utc": "2023-11-07T05:31:56Z",
"password_rotation_status": "Disabled",
"last_password_rotation_utc": "2023-11-07T05:31:56Z"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}type — see Required vs ignored fields by SecretType for the per-type matrix.
https://{hostname}/EkranACB server in the Playground.Permissions required
The user owning the Access Token must have Editor or Owner role on the target parent folder.Secret type → required target field
type | Required target field |
|---|---|
ADAccount | domain |
WindowsAccount | computer_name |
UnixAccountSSH, UnixAccountTelnet, MSSQLAccount | server |
WebAccount | url |
login. For UnixAccountSSH, the credentials can be either a password (password field) or an SSH key (ssh_key field).
v1.4 changes
rotation.rotate_every_minis now required with minimum 1. To disable rotation, setrotation: { enabled: false, rotate_every_min: 1 }.- New
check_passwordfield for configuring heartbeat checks — see CheckPassword.
Errors
See Status codes. Common errors:- 400 Bad Request — missing required field for the secret type, or invalid configuration object.
- 403 Forbidden — user lacks Editor/Owner role on the parent folder.
- 409 Conflict — secret name already exists in the parent folder.
Related
Data models — fields by SecretType
Update secret
Bulk add
Add folder
Authorizations
Access token for authentication
Body
Name of the secret
512Type of secret
None, UnixAccountSSH, UnixAccountTelnet, WindowsAccount, ADAccount, WebAccount, MSSQLAccount Login username
512Description of the secret
2000The password value
Show child attributes
Show child attributes
ID of the parent folder
x >= 0Name of the parent folder
512Domain for AD accounts
512Computer name for Windows/Unix accounts
512URL for web accounts
2000Server for database accounts
512List of computers
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Whether to record activities for this secret
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Response
Secret created successfully
Unique identifier of the secret
Name of the secret
Type of secret
None, UnixAccountSSH, UnixAccountTelnet, WindowsAccount, ADAccount, WebAccount, MSSQLAccount Login username
Description of the secret
ID of the parent folder
Domain for AD accounts
Computer name for Windows/Unix accounts
URL for web accounts
Server for database accounts
List of computers
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Whether to record activities for this secret
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Status of the last password check (heartbeat)
None, Valid, Invalid, Failed UTC timestamp of the last password check
Status of password rotation
Disabled, Enabled, Failed UTC timestamp of the last password rotation