GET
/api/public/v1/vault-credentialsList Vault credentials
Stored passwords, cards, API keys and secure notes — **without their secrets**. A credential’s payload is encrypted at rest and never appears in a list. Fetch one by id to reveal it, which is also what writes the audit event: a secret nobody can tell you looked at is not a secret you can keep.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
vault:admin
Query Parameters
| Name | Type | Required | Description |
|---|---|---|---|
limit | number | Optional | Maximum number of items to return (1-100).Default: 20 |
offset | number | Optional | Number of items to skip before starting to collect the result set.Default: 0 |
sortBy | string | Optional | Field to sort by. Allowed values vary by endpoint.Default: createdAt |
sortOrder | string asc desc | Optional | Sort direction.Default: desc |
search | string | Optional | Free-text search across the resource’s primary fields. |
createdAfter | string | Optional | ISO 8601 timestamp — only return items created after this time. |
createdBefore | string | Optional | ISO 8601 timestamp — only return items created before this time. |
updatedAfter | string | Optional | ISO 8601 timestamp — only return items updated after this time. |
type | string PASSWORD CREDIT_CARD API_KEY SECURE_NOTE | Optional | Narrow to one kind. |
parentId | string | Optional | One folder’s credentials. Pass `root` for the top level. |
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/vault-credentials" \
-H "Authorization: Bearer your_access_token"200Example response
json
{
"message": "Vault credentials retrieved successfully!",
"content": {
"credentials": [
{
"id": "vcr_9002",
"referenceId": 51,
"name": "Stripe live key",
"type": "API_KEY",
"username": null,
"email": null,
"website": "https://dashboard.stripe.com",
"notes": null,
"tags": [
"payments"
],
"parentId": "vdoc_0002",
"lastAccessedAt": "2026-08-27T14:03:00.000Z",
"createdAt": "2026-02-01T10:00:00.000Z",
"updatedAt": "2026-02-01T10:00:00.000Z"
}
],
"pagination": {
"total": 42,
"limit": 20,
"offset": 0,
"hasMore": true
}
}
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.
Vault → Credentials
/vault