GET
/api/public/v1/vault-credentials/{credentialId}Reveal a Vault credential
Returns the credential with its secret decrypted in `sensitiveData`. This is the read that hands over an actual secret, so it does three things the list does not: it checks folder membership, it stamps `lastAccessedAt`, and it writes a VIEW audit event visible to Vault admins. Reaching a credential through the API leaves exactly the same trail as opening it in the console — there is no quieter way in.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
vault:admin
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
credentialId | string | Required | Credential ID. |
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/vault-credentials/{credentialId}" \
-H "Authorization: Bearer your_access_token"200Example response
json
{
"message": "Credential fetched successfully.",
"content": {
"credential": {
"id": "vcr_9002",
"referenceId": 51,
"name": "Stripe live key",
"type": "API_KEY",
"username": null,
"email": null,
"website": "https://dashboard.stripe.com",
"notes": null,
"tags": [
"payments"
],
"parentId": "vdoc_0002",
"lastAccessedAt": "2026-08-27T14:03:00.000Z",
"createdAt": "2026-02-01T10:00:00.000Z",
"updatedAt": "2026-02-01T10:00:00.000Z"
},
"sensitiveData": {
"apiKey": "sk_live_…"
}
}
}403Example response
json
{
"message": "You do not have access to that credential."
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.