GET
/api/public/v1/vault-credentials/{credentialId}

Reveal a Vault credential

Returns the credential with its secret decrypted in `sensitiveData`. This is the read that hands over an actual secret, so it does three things the list does not: it checks folder membership, it stamps `lastAccessedAt`, and it writes a VIEW audit event visible to Vault admins. Reaching a credential through the API leaves exactly the same trail as opening it in the console — there is no quieter way in.

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

vault:admin

Path Parameters

NameTypeRequiredDescription
credentialIdstringRequiredCredential ID.
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/vault-credentials/{credentialId}" \
  -H "Authorization: Bearer your_access_token"
200Example response
json
{
  "message": "Credential fetched successfully.",
  "content": {
    "credential": {
      "id": "vcr_9002",
      "referenceId": 51,
      "name": "Stripe live key",
      "type": "API_KEY",
      "username": null,
      "email": null,
      "website": "https://dashboard.stripe.com",
      "notes": null,
      "tags": [
        "payments"
      ],
      "parentId": "vdoc_0002",
      "lastAccessedAt": "2026-08-27T14:03:00.000Z",
      "createdAt": "2026-02-01T10:00:00.000Z",
      "updatedAt": "2026-02-01T10:00:00.000Z"
    },
    "sensitiveData": {
      "apiKey": "sk_live_…"
    }
  }
}
403Example response
json
{
  "message": "You do not have access to that credential."
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Vault → Credentials
/vault
  1. Open a credential and reveal it.