Get secret credentials (pre-v1.3 endpoint)
curl --request POST \
--url https://your-syteca-host/SytecaACB/get_secret_details \
--header 'Content-Type: application/json' \
--data '
{
"accessToken": "<string>",
"secretId": 2
}
'import requests
url = "https://your-syteca-host/SytecaACB/get_secret_details"
payload = {
"accessToken": "<string>",
"secretId": 2
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({accessToken: '<string>', secretId: 2})
};
fetch('https://your-syteca-host/SytecaACB/get_secret_details', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/get_secret_details",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'accessToken' => '<string>',
'secretId' => 2
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/get_secret_details"
payload := strings.NewReader("{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/get_secret_details")
.header("Content-Type", "application/json")
.body("{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/get_secret_details")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}"
response = http.request(request)
puts response.read_body{
"login": "<string>",
"password": "<string>",
"ssh_key": {
"private_key": "<string>",
"pass_phrase": "<string>"
},
"domain": "<string>",
"server": "<string>",
"computer_name": "<string>",
"url": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Endpoints
Get Secret Details (Old)
Pre-v1.3 Syteca ACB endpoint for retrieving secret credentials with the Access Token in the JSON request body. Superseded by GET /api/secrets//password but still supported for backward compatibility.
POST
/
get_secret_details
Get secret credentials (pre-v1.3 endpoint)
curl --request POST \
--url https://your-syteca-host/SytecaACB/get_secret_details \
--header 'Content-Type: application/json' \
--data '
{
"accessToken": "<string>",
"secretId": 2
}
'import requests
url = "https://your-syteca-host/SytecaACB/get_secret_details"
payload = {
"accessToken": "<string>",
"secretId": 2
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({accessToken: '<string>', secretId: 2})
};
fetch('https://your-syteca-host/SytecaACB/get_secret_details', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/get_secret_details",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'accessToken' => '<string>',
'secretId' => 2
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/get_secret_details"
payload := strings.NewReader("{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/get_secret_details")
.header("Content-Type", "application/json")
.body("{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/get_secret_details")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"accessToken\": \"<string>\",\n \"secretId\": 2\n}"
response = http.request(request)
puts response.read_body{
"login": "<string>",
"password": "<string>",
"ssh_key": {
"private_key": "<string>",
"pass_phrase": "<string>"
},
"domain": "<string>",
"server": "<string>",
"computer_name": "<string>",
"url": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Retrieves a secret’s credentials (login, password, SSH key) using the pre-v1.3 authentication model — the Access Token goes in the JSON request body, not the
Authorization header. Still supported for backward compatibility, but new consumers should use GET /api/secrets/{id}/password instead.
This endpoint passes the Access Token in the request body rather than a header. This is the original ACB authentication pattern preserved for backward compatibility — the response shape and field set are otherwise equivalent to the new endpoint.
For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Where to get the Secret ID
The Secret ID is visible on the Automation tab of the Edit Secret page — see Find the Secret ID.Permissions required
The user owning the Access Token must have at least PAM User role on the secret.Errors
See Status codes. Common errors:- 401 Unauthorized — expired or invalid Access Token.
- 403 Forbidden — user lacks the PAM User role (or higher) on this secret.
- 404 Not Found — secret doesn’t exist or isn’t visible to the authenticated user.
Related
Get secret credentials (new)
The v1.3+ equivalent with header-based auth.
Get access token
How to obtain the Access Token this endpoint requires.
API reference
Status codes, rate limiting.
Secret permissions
Role types and permission grants.
Body
application/json
Response
Credentials returned successfully
Login name.
Password value.
SSH key data (UnixAccountSSH only).
Show child attributes
Show child attributes
AD domain (ADAccount only).
Server hostname (Unix/MSSQL accounts).
Target computer (WindowsAccount only).
Application URL (WebAccount only).