GET
/api/public/v1/vault-credentials

List Vault credentials

Stored passwords, cards, API keys and secure notes — **without their secrets**. A credential’s payload is encrypted at rest and never appears in a list. Fetch one by id to reveal it, which is also what writes the audit event: a secret nobody can tell you looked at is not a secret you can keep.

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

vault:admin

Query Parameters

NameTypeRequiredDescription
limitnumberOptionalMaximum number of items to return (1-100).Default: 20
offsetnumberOptionalNumber of items to skip before starting to collect the result set.Default: 0
sortBystringOptionalField to sort by. Allowed values vary by endpoint.Default: createdAt
sortOrderstring
asc
desc
OptionalSort direction.Default: desc
searchstringOptionalFree-text search across the resource’s primary fields.
createdAfterstringOptionalISO 8601 timestamp — only return items created after this time.
createdBeforestringOptionalISO 8601 timestamp — only return items created before this time.
updatedAfterstringOptionalISO 8601 timestamp — only return items updated after this time.
typestring
PASSWORD
CREDIT_CARD
API_KEY
SECURE_NOTE
OptionalNarrow to one kind.
parentIdstringOptionalOne folder’s credentials. Pass `root` for the top level.
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/vault-credentials" \
  -H "Authorization: Bearer your_access_token"
200Example response
json
{
  "message": "Vault credentials retrieved successfully!",
  "content": {
    "credentials": [
      {
        "id": "vcr_9002",
        "referenceId": 51,
        "name": "Stripe live key",
        "type": "API_KEY",
        "username": null,
        "email": null,
        "website": "https://dashboard.stripe.com",
        "notes": null,
        "tags": [
          "payments"
        ],
        "parentId": "vdoc_0002",
        "lastAccessedAt": "2026-08-27T14:03:00.000Z",
        "createdAt": "2026-02-01T10:00:00.000Z",
        "updatedAt": "2026-02-01T10:00:00.000Z"
      }
    ],
    "pagination": {
      "total": 42,
      "limit": 20,
      "offset": 0,
      "hasMore": true
    }
  }
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Vault → Credentials
/vault