Get secret credentials
curl --request GET \
--url https://your-syteca-host/SytecaACB/api/secrets/{id}/password \
--header 'Authorization: <api-key>'import requests
url = "https://your-syteca-host/SytecaACB/api/secrets/{id}/password"
headers = {"Authorization": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: '<api-key>'}};
fetch('https://your-syteca-host/SytecaACB/api/secrets/{id}/password', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/secrets/{id}/password",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/secrets/{id}/password"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://your-syteca-host/SytecaACB/api/secrets/{id}/password")
.header("Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/secrets/{id}/password")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": 123,
"name": "<string>",
"type": "None",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"ssh_key": {
"private_key": "<string>",
"pass_phrase": "<string>"
},
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Endpoints
Get Secret Credentials
Syteca ACB REST API endpoint to retrieve a secret’s actual credentials — login, password, and (for SSH secrets) the SSH private key. The most frequently called ACB endpoint.
GET
/
api
/
secrets
/
{id}
/
password
Get secret credentials
curl --request GET \
--url https://your-syteca-host/SytecaACB/api/secrets/{id}/password \
--header 'Authorization: <api-key>'import requests
url = "https://your-syteca-host/SytecaACB/api/secrets/{id}/password"
headers = {"Authorization": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: '<api-key>'}};
fetch('https://your-syteca-host/SytecaACB/api/secrets/{id}/password', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/secrets/{id}/password",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/secrets/{id}/password"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://your-syteca-host/SytecaACB/api/secrets/{id}/password")
.header("Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/secrets/{id}/password")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": 123,
"name": "<string>",
"type": "None",
"login": "<string>",
"description": "<string>",
"password": "<string>",
"ssh_key": {
"private_key": "<string>",
"pass_phrase": "<string>"
},
"domain": "<string>",
"computer_name": "<string>",
"url": "<string>",
"server": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Retrieves a secret’s actual credentials — login, password, and (for SSH-type secrets) the SSH private key. The canonical endpoint that automation consumers call to retrieve credentials at deployment time, runtime, or scheduled-task execution. The most frequently called ACB endpoint.
For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Permissions required
The user owning the Access Token must have at least PAM User role on the secret.Check-out and approval interactions
- If the secret is configured with check-out enabled, this call checks the secret out — and the next caller is blocked until check-in.
- If the secret requires approval, the call returns 403 until an approver grants access.
Treat credentials returned from this endpoint as ephemeral. Don’t write them to disk, log them, or cache them beyond the lifetime of the operation that needed them. The point of using ACB is so credentials never live anywhere outside the secrets vault and the in-memory consumer context.
Response shape varies by SecretType
The response includes only the fields relevant to the secret’stype — domain for ADAccount, server for Unix/MSSQL, computer_name for WindowsAccount, url for WebAccount, ssh_key for UnixAccountSSH with key auth, etc.
Rate limit
60 requests per minute per Access Token. This is intentionally higher than other endpoints — credential retrieval is the highest-volume API operation.Errors
See Status codes. Common errors:- 403 Forbidden — user lacks PAM User role, OR the secret requires approval and hasn’t been approved.
- 404 Not Found — secret doesn’t exist.
- 409 Conflict — secret is currently checked out by another user (when check-out is enabled).
Related
Get secret
Read metadata without retrieving credentials.
Get secret details (old)
Pre-v1.3 equivalent.
Rotate password
Trigger rotation after retrieval if policy requires.
Force check-in
Release a checked-out secret.
Authorizations
Access token for authentication
Path Parameters
The ID of the secret to retrieve credentials for
Required range:
x >= 1Response
Secret credentials retrieved successfully
Unique identifier of the secret
Name of the secret
Type of secret
Available options:
None, UnixAccountSSH, UnixAccountTelnet, WindowsAccount, ADAccount, WebAccount, MSSQLAccount Login username
Description of the secret
The password value
Show child attributes
Show child attributes
Domain for AD accounts
Computer name for Windows/Unix accounts
URL for web accounts
Server for database accounts