Skip to main content

Credential vault

  • Reference

Manage credential entries of username/password, certificate, and token types, with support for external vault integrations.

To authorize, use a valid OAuth token.

Notes about compatibility:

  • Operations marked as early adopter or preview may be changed in non-compatible ways, although we try to avoid this.
  • We may add new enum constants without incrementing the API version; thus, clients need to handle unknown enum constants gracefully.
Latest (V1)
npm install @dynatrace-sdk/client-credential-vault

credentialVaultEntriesClient​

import { credentialVaultEntriesClient } from '@dynatrace-sdk/client-credential-vault';

createCredentialVaultEntry​

credentialVaultEntriesClient.createCredentialVaultEntry(config): Promise<CredentialsId>

Creates a new credential entry. | maturity=EARLY_ADOPTER

Required scope: credential-vault:entries:write

The body must not provide an ID. An ID is assigned automatically by the Dynatrace server.

Parameters​

NameType
config.body*requiredCredentials

Returns​

Return typeStatus codeDescription
CredentialsId201Success. The new credential entry has been created. The response contains the ID of the entry.

Throws​

Error TypeError Message
ErrorResponseEnvelopeErrorClient side error. | Server side error.

Code example

import { credentialVaultEntriesClient } from "@dynatrace-sdk/client-credential-vault";

const data =
await credentialVaultEntriesClient.createCredentialVaultEntry(
{
body: {
name: "...",
scopes: ["APP_ENGINE"],
type: "AWS_MONITORING_KEY_BASED",
},
},
);

deleteCredentialVaultEntry​

credentialVaultEntriesClient.deleteCredentialVaultEntry(config): Promise<void>

Deletes the specified credential entry. | maturity=EARLY_ADOPTER

Required scope: credential-vault:entries:admin

Provide the credential ID in the path.

Parameters​

NameTypeDescription
config.entryId*requiredstringThe ID of the credential entry to be deleted.

Returns​

Return typeStatus codeDescription
void204Success. The credential entry has been deleted. The response doesn't have a body.

Throws​

Error TypeError Message
ErrorResponseEnvelopeErrorClient side error. | Server side error.

Code example

import { credentialVaultEntriesClient } from "@dynatrace-sdk/client-credential-vault";

const data =
await credentialVaultEntriesClient.deleteCredentialVaultEntry(
{ entryId: "..." },
);

getCredentialVaultEntry​

credentialVaultEntriesClient.getCredentialVaultEntry(config): Promise<CredentialsResponseElement>

Gets the metadata of the specified credential entry. | maturity=EARLY_ADOPTER

Required scope: credential-vault:entries:read

The credential entry itself (e.g. username/certificate and password) is not included in the response.

Parameters​

NameTypeDescription
config.entryId*requiredstringThe ID of the required credential entry.

Returns​

Return typeStatus codeDescription
CredentialsResponseElement200Success. The response contains the metadata of the credential entry.

Throws​

Error TypeError Message
ErrorResponseEnvelopeErrorClient side error. | Server side error.

Code example

import { credentialVaultEntriesClient } from "@dynatrace-sdk/client-credential-vault";

const data =
await credentialVaultEntriesClient.getCredentialVaultEntry(
{ entryId: "..." },
);

listCredentialVaultEntries​

credentialVaultEntriesClient.listCredentialVaultEntries(config): Promise<CredentialsList>

Lists all credential entries in your environment. | maturity=EARLY_ADOPTER

Required scope: credential-vault:entries:read

The credential entry itself (username/certificate and password) is not included in the response.

Parameters​

NameTypeDescription
config.namestringFilters the result by name. Enclose the value in quotation marks to match the whole phrase. Case-insensitive.
config.pageKeystring

The cursor for the next page of results. You can find it in the nextPageKey field of the previous response.

The first page is always returned if you don't specify the page-key query parameter.

When the page-key is set to obtain subsequent pages, you must omit all other query parameters.

config.pageSizenumber

The amount of credential vault entries in a single response payload.

The maximal allowed page size is 500.

If not set, 100 is used.

config.scopestringFilters the result by the specified scope.
config.type"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"Filters the result by the specified credential type.
config.userstringFilters the result to credentials accessible to the specified user (those they own or those shared with everyone).

Returns​

Return typeStatus codeDescription
CredentialsList200Success

Throws​

Error TypeError Message
ErrorResponseEnvelopeErrorClient side error. | Server side error.

Code example

import { credentialVaultEntriesClient } from "@dynatrace-sdk/client-credential-vault";

const data =
await credentialVaultEntriesClient.listCredentialVaultEntries();

updateCredentialVaultEntry​

credentialVaultEntriesClient.updateCredentialVaultEntry(config): Promise<void>

Updates the specified credential entry. | maturity=EARLY_ADOPTER

Required scope: credential-vault:entries:admin

The body must not provide an ID. The ID should be provided in the path.

Parameters​

NameTypeDescription
config.body*requiredCredentials
config.entryId*requiredstringThe ID of the credential entry to be updated.

Returns​

Return typeStatus codeDescription
void204Success. The credential entry has been updated. The response doesn't have a body.

Throws​

Error TypeError Message
ErrorResponseEnvelopeErrorClient side error. | Server side error.

Code example

import { credentialVaultEntriesClient } from "@dynatrace-sdk/client-credential-vault";

const data =
await credentialVaultEntriesClient.updateCredentialVaultEntry(
{
entryId: "...",
body: {
name: "...",
scopes: ["APP_ENGINE"],
type: "AWS_MONITORING_KEY_BASED",
},
},
);

Types​

AWSKeyBasedCredentialsDto​

A credentials set of the AWS_MONITORING_KEY_BASED type.

NameTypeDescription
accessKeyID*requiredstringAccess Key ID of the credentials set.
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
awsPartition*required"CHINA" | "DEFAULT" | "US_GOV"AWS partition of the credential.
descriptionstringA short description of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

secretKey*requiredstringSecret access key of the credential.
type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

AWSRoleBasedCredentials​

A credentials set of the AWS_MONITORING_ROLE_BASED type.

NameTypeDescription
accountID*requiredstringAmazon account ID of the credential.
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
descriptionstringA short description of the credentials set.
iamRole*requiredstringThe IAM role name of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

AzureClientSecret​

Synchronization credentials with Azure Key Vault using client secret authentication method

NameTypeDescription
clientIdstringClient (application) ID of Azure application in Azure Active Directory which has permission to access secrets in Azure Key Vault.
clientSecretstringClient secret generated for Azure application in Azure Active Directory used for proving identity when requesting a token used later for accessing secrets in Azure Key Vault.
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tenantIdstringTenant (directory) ID of Azure application in Azure Active Directory which has permission to access secrets in Azure Key Vault.
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultUrlstringExternal vault URL.

AzureClientSecretConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
clientIdstring
clientSecretstring
credentialsUsedForExternalSynchronizationArray<string>
passwordSecretNamestring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tenantIdstring
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernameSecretNamestring
vaultUrlstring

CertificateCredentials​

A credentials set of the CERTIFICATE type.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
certificate*requiredstringString containing the certificate file bytes encoded in Base64 without carriage return.
certificateFormat*required"UNKNOWN" | "PEM" | "PKCS12"The certificate format. Use PEM for PEM certificates and PKCS12 for PFX and P12 certificates.
descriptionstringA short description of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
password*requiredstringThe password of the credential encoded in Base64. Must be empty for PEM certificates.
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

ConstraintViolation​

Information about a single constraint violation.

NameTypeDescription
contextConstraintViolationContext

Structured context of the constraint violation. Well known keys that can be present are:

  • reason -> Additional reasoning behind the occurred violation.
  • pipeline -> Pipeline related to the violation.
  • endpoint -> Endpoint related to the violation.
  • stage -> Stage related to the violation.
  • processor -> Processor related to the violation.
  • routingRule -> Routing rule related to the violation.
message*requiredstringDescription of the constraint violation.

ConstraintViolationContext​

Structured context of the constraint violation. Well known keys that can be present are:

  • reason -> Additional reasoning behind the occurred violation.
  • pipeline -> Pipeline related to the violation.
  • endpoint -> Endpoint related to the violation.
  • stage -> Stage related to the violation.
  • processor -> Processor related to the violation.
  • routingRule -> Routing rule related to the violation.

type: Record<string, string>

ConstraintViolationDetails​

List of encountered constraint violations.

NameTypeDescription
constraintViolations*requiredArray<ConstraintViolation>List of encountered constraint violations.
type*required"constraintViolation"

Defines the actual set of fields depending on the value. See one of the following objects:

  • constraintViolation -> ConstraintViolationDetails

CredentialAccessData​

The set of entities allowed to use the credential.

NameType
idstring
type"APPLICATION" | "UNKNOWN" | "USER"

CredentialUsageHandler​

Keeps information about credential's usage.

NameTypeDescription
countnumberThe number of uses.
typestringType of usage.

Credentials​

A set of credentials for synthetic monitors.

The actual set of fields depends on the type of credentials. Find the list of actual objects in the description of the type field or see Credential vault API - JSON models.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
descriptionstringA short description of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

CredentialsId​

A short representation of the credentials set.

NameTypeDescription
id*requiredstringThe ID of the credentials set.

CredentialsList​

A list of credentials sets for Synthetic monitors.

NameTypeDescription
credentials*requiredArray<CredentialsResponseElement>A list of credentials sets for Synthetic monitors.
nextPageKeystring
pageSizenumber
totalCountnumber

CredentialsResponseElement​

Metadata of the credentials set.

NameTypeDescription
allowContextlessRequestsbooleanAllow access without app context, for example, from ad hoc functions in Workflows (requires the APP_ENGINE scope).
allowedEntities*requiredArray<CredentialAccessData>The set of entities allowed to use the credential.
credentialUsageSummary*requiredArray<CredentialUsageHandler>The list contains summary data related to the use of credentials.
description*requiredstringA short description of the credentials set.
externalVaultExternalVaultConfigConfiguration for external vault synchronization for username and password credentials.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
owner*requiredstringThe owner of the credential (user for which used API token was created).
ownerAccessOnly*requiredbooleanFlag indicating that this credential is visible only to the owner.
scope"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopesArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">The set of scopes of the credentials set.
type*required"UNKNOWN" | "AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"The type of the credentials set.

CyberArkAllowedLocationConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
accountNamestring
applicationIdstring
certificatestring
credentialsUsedForExternalSynchronizationArray<string>
folderNamestring
passwordSecretNamestring
safeNamestring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernameSecretNamestring
vaultUrlstring

CyberArkAllowedLocationDto​

Synchronization credentials with CyberArk Vault using allowed machines (location) authentication method.

NameTypeDescription
accountName*requiredstringAccount name that stores the username and password to retrieve and synchronize with the Dynatrace Credential Vault: This is NOT the name of the account logged into the CyberArk Central Credential Provider.
applicationId*requiredstringApplication ID connected to CyberArk Vault.
certificatestring[Recommended] Certificate used for authentication to CyberArk application. ID of certificate credential saved in Dynatrace CV.
folderNamestring[Optional] Folder name where credentials in CyberArk Vault are stored. Default folder name is 'Root'.
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
safeName*requiredstringSafe name connected to CyberArk Vault.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultUrlstringExternal vault URL.

CyberArkUsernamePassword​

Synchronization credentials with CyberArk Vault using username password authentication method.

NameTypeDescription
accountName*requiredstringAccount name that stores the username and password to retrieve and synchronize with the Dynatrace Credential Vault: This is NOT the name of the account logged into the CyberArk Central Credential Provider.
applicationId*requiredstringApplication ID connected to CyberArk Vault.
certificatestring[Recommended] Certificate used for authentication to CyberArk application. ID of certificate credential saved in Dynatrace CV.
folderNamestring[Optional] Folder name where credentials in CyberArk Vault are stored. Default folder name is 'Root'.
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
safeName*requiredstringSafe name connected to CyberArk Vault.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernamePasswordForCPM*requiredstringDynatrace credential ID of the username-password pair used for authentication to the CyberArk Central Credential Provider
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultUrlstringExternal vault URL.

CyberArkUsernamePasswordConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
accountNamestring
applicationIdstring
certificatestring
credentialsUsedForExternalSynchronizationArray<string>
folderNamestring
passwordSecretNamestring
safeNamestring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernamePasswordForCPMstring
usernameSecretNamestring
vaultUrlstring

ErrorResponse​

Basic information of the encountered error.

NameTypeDescription
code*requirednumberThe returned HTTP status code.
detailsErrorResponseDetailsDetailed information of the error.
message*requiredstringDescription of the encountered error.

ErrorResponseDetails​

Detailed information of the error.

NameTypeDescription
type*required"constraintViolation"

Defines the actual set of fields depending on the value. See one of the following objects:

  • constraintViolation -> ConstraintViolationDetails

ErrorResponseEnvelope​

Encloses the encountered error.

NameTypeDescription
error*requiredErrorResponseBasic information of the encountered error.

ExternalVault​

Information for synchronization credentials with external vault

NameTypeDescription
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultUrlstringExternal vault URL.

ExternalVaultConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
credentialsUsedForExternalSynchronizationArray<string>
passwordSecretNamestring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernameSecretNamestring
vaultUrlstring

HashicorpApprole​

Synchronization credentials with HashiCorp Vault using appRole authentication method

NameTypeDescription
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
pathToCredentials*requiredstringPath to folder where credentials in HashiCorp Vault are stored.
roleId*requiredstringRole ID is similar to username when you want to authenticate in HashiCorp Vault using AppRole.
secretId*requiredstringSecret ID is similar to password when you want to authenticate in HashiCorp Vault using AppRole. ID of token representing secret ID saved in Dynatrace CV.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultNamespace*requiredstringVault namespace in HashiCorp Vault. It is an information you set as environmental variable VAULT_NAMESPACE if you are accessing HashiCorp Vault from command line.
vaultUrlstringExternal vault URL.

HashicorpApproleConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
credentialsUsedForExternalSynchronizationArray<string>
passwordSecretNamestring
pathToCredentialsstring
roleIdstring
secretIdstring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernameSecretNamestring
vaultNamespacestring
vaultUrlstring

HashicorpCertificate​

Synchronization credentials with HashiCorp Vault using certificate authentication method

NameTypeDescription
certificatestringID of certificate saved in Dynatrace CV. Using this certificate you can authenticate to your HashiCorp Vault.
locationForSynchronizationIdstringId of a location used by the synchronizing monitor
passwordSecretNamestringThe name of the secret saved in external vault where password is stored.
pathToCredentialsstringPath to folder where credentials in HashiCorp Vault are stored.
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto
tokenSecretNamestringThe name of the secret saved in external vault where token is stored.
usernameSecretNamestringThe name of the secret saved in external vault where username is stored.
vaultUrlstringExternal vault URL.

HashicorpCertificateConfig​

Configuration for external vault synchronization for username and password credentials.

NameTypeDescription
certificatestring
credentialsUsedForExternalSynchronizationArray<string>
passwordSecretNamestring
pathToCredentialsstring
sourceAuthMethod"AZURE_KEY_VAULT_CLIENT_SECRET" | "CYBERARK_VAULT_ALLOWED_LOCATION" | "CYBERARK_VAULT_USERNAME_PASSWORD" | "HASHICORP_VAULT_APPROLE" | "HASHICORP_VAULT_CERTIFICATE"

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig
tokenSecretNamestring
type"AZURE_CERTIFICATE_MODEL" | "AZURE_CLIENT_SECRET_MODEL" | "CYBERARK_VAULT_ALLOWED_LOCATION_MODEL" | "CYBERARK_VAULT_USERNAME_PASSWORD_MODEL" | "HASHICORP_APPROLE_MODEL" | "HASHICORP_CERTIFICATE_MODEL"
usernameSecretNamestring
vaultUrlstring

PublicCertificateCredentials​

A credentials set of the PUBLIC_CERTIFICATE type.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
certificate*requiredstringThe certificate in the string format.
certificateFormat*required"UNKNOWN" | "PEM" | "PKCS12"The certificate format.
descriptionstringA short description of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
password*requiredstringThe password of the credential (not supported).
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

SNMPV3Credentials​

A credentials set of the SNMPV3 type.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
authenticationPasswordstringThe authentication password in the string format (should not be empty for AUTH_PRIV and AUTH_NO_PRIV security levels)
authenticationProtocol"MD5" | "SHA" | "SHA224" | "SHA256" | "SHA384" | "SHA512"The authentication protocol, supported protocols: MD5, SHA, SHA224, SHA256, SHA384, SHA512
descriptionstringA short description of the credentials set.
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
privacyPasswordstringThe privacy password in the string format (should not be empty for AUTH_PRIV security level)
privacyProtocol"AES" | "AES192" | "AES192C" | "AES256" | "AES256C" | "DES"The privacy protocol
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

securityLevel*required"AUTH_NO_PRIV" | "AUTH_PRIV" | "NO_AUTH_NO_PRIV"The security level, supported levels: AUTH_PRIV, NO_AUTH_NO_PRIV, AUTH_NO_PRIV
type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials
username*requiredstringUser name value

TokenCredentials​

A credentials set of the TOKEN type.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
descriptionstringA short description of the credentials set.
externalVaultExternalVaultInformation for synchronization credentials with external vault
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

tokenstringToken in the string format.
type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

UserPasswordCredentials​

A credentials set of the USERNAME_PASSWORD type.

NameTypeDescription
allowContextlessRequestsbooleanAllow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).
allowedEntitiesArray<CredentialAccessData>The set of entities allowed to use the credential.
descriptionstringA short description of the credentials set.
externalVaultExternalVaultInformation for synchronization credentials with external vault
idstringThe ID of the credentials set.
name*requiredstringThe name of the credentials set.
ownerAccessOnlybooleanThe credentials set is available to every user (false) or to owner only (true).
passwordstringThe password of the credential.
scopeDEPRECATED"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC"The scope of the credentials set.
scopes*requiredArray<"APP_ENGINE" | "EXTENSION" | "EXTENSION_AUTHENTICATION" | "SYNTHETIC">

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

type*required"AWS_MONITORING_KEY_BASED" | "AWS_MONITORING_ROLE_BASED" | "CERTIFICATE" | "PUBLIC_CERTIFICATE" | "SNMPV3" | "TOKEN" | "USERNAME_PASSWORD"

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials
userstringThe username of the credentials set.

Enums​

CredentialAccessDataType​

⚠️ Deprecated Use literal values.

Enum keys​

Application | Unknown | User

CredentialsResponseElementScope​

⚠️ Deprecated Use literal values.

The scope of the credentials set.

Enum keys​

AppEngine | Extension | ExtensionAuthentication | Synthetic

CredentialsResponseElementScopesItem​

⚠️ Deprecated Use literal values.

The set of scopes of the credentials set.

Enum keys​

AppEngine | Extension | ExtensionAuthentication | Synthetic

CredentialsResponseElementType​

⚠️ Deprecated Use literal values.

The type of the credentials set.

Enum keys​

AwsMonitoringKeyBased | AwsMonitoringRoleBased | Certificate | PublicCertificate | Snmpv3 | Token | Unknown | UsernamePassword

CredentialsScope​

⚠️ Deprecated Use literal values.

The scope of the credentials set.

Enum keys​

AppEngine | Extension | ExtensionAuthentication | Synthetic

CredentialsScopesItem​

⚠️ Deprecated Use literal values.

The set of scopes of the credentials set.

Limitations: CredentialsScope.APP_ENGINE is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.

Enum keys​

AppEngine | Extension | ExtensionAuthentication | Synthetic

CredentialsType​

⚠️ Deprecated Use literal values.

Defines the actual set of fields depending on the value. See one of the following objects:

  • CERTIFICATE -> CertificateCredentials
  • PUBLIC_CERTIFICATE -> PublicCertificateCredentials
  • USERNAME_PASSWORD -> UserPasswordCredentials
  • TOKEN -> TokenCredentials
  • SNMPV3 -> SNMPV3Credentials
  • AWS_MONITORING_KEY_BASED -> AWSKeyBasedCredentialsDto
  • AWS_MONITORING_ROLE_BASED -> AWSRoleBasedCredentials

Enum keys​

AwsMonitoringKeyBased | AwsMonitoringRoleBased | Certificate | PublicCertificate | Snmpv3 | Token | UsernamePassword

ErrorResponseDetailsType​

⚠️ Deprecated Use literal values.

Defines the actual set of fields depending on the value. See one of the following objects:

  • constraintViolation -> ConstraintViolationDetails

Enum keys​

ConstraintViolation

ExternalVaultConfigSourceAuthMethod​

⚠️ Deprecated Use literal values.

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApproleConfig
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificateConfig
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecretConfig
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePasswordConfig
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationConfig

Enum keys​

AzureKeyVaultClientSecret | CyberarkVaultAllowedLocation | CyberarkVaultUsernamePassword | HashicorpVaultApprole | HashicorpVaultCertificate

ExternalVaultConfigType​

⚠️ Deprecated Use literal values.

Enum keys​

AzureCertificateModel | AzureClientSecretModel | CyberarkVaultAllowedLocationModel | CyberarkVaultUsernamePasswordModel | HashicorpApproleModel | HashicorpCertificateModel

ExternalVaultSourceAuthMethod​

⚠️ Deprecated Use literal values.

Defines the actual set of fields depending on the value. See one of the following objects:

  • HASHICORP_VAULT_APPROLE -> HashicorpApprole
  • HASHICORP_VAULT_CERTIFICATE -> HashicorpCertificate
  • AZURE_KEY_VAULT_CLIENT_SECRET -> AzureClientSecret
  • CYBERARK_VAULT_USERNAME_PASSWORD -> CyberArkUsernamePassword
  • CYBERARK_VAULT_ALLOWED_LOCATION -> CyberArkAllowedLocationDto

Enum keys​

AzureKeyVaultClientSecret | CyberarkVaultAllowedLocation | CyberarkVaultUsernamePassword | HashicorpVaultApprole | HashicorpVaultCertificate

ListCredentialVaultEntriesQueryType​

⚠️ Deprecated Use literal values.

Enum keys​

AwsMonitoringKeyBased | AwsMonitoringRoleBased | Certificate | Snmpv3 | Token | UsernamePassword

Still have questions?
Find answers in the Dynatrace Community