> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-hypeship-egress-allowlists.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a vault's public key for browser-encrypted credential values

> Returns the public key that custom credential collection web apps use to encrypt values in the browser. Use this only if you run your own credential collection web app and want values encrypted in the browser, sent to your backend still encrypted, and forwarded to Kernel's API still encrypted. In every other case, including server-side code that already holds the plaintext, use value. The page encrypts each value to this key, your backend forwards the ciphertext unchanged as encrypted_value when creating or updating a credential item in this vault, and Kernel decrypts it.



## OpenAPI

````yaml https://api.onkernel.com/spec.json get /vaults/{id_or_name}/encryption_key
openapi: 3.1.0
info:
  description: Developer tools and cloud infrastructure for AI agents to use web browsers
  title: Kernel API
  version: 0.1.0
servers:
  - description: API Server
    url: https://api.onkernel.com
security:
  - bearerAuth: []
tags:
  - description: Search the web and retrieve content for selected results.
    name: Search
  - description: Create and manage browser sessions.
    name: Browsers
  - description: Control mouse, keyboard, and screen on the browser instance.
    name: Browser Computer Controls
  - description: >-
      Execute Playwright code against the browser instance and manage the
      executors it runs in.
    name: Browser Playwright
  - description: Execute JavaScript in the browser instance's persistent Browser REPL.
    name: Browser REPL
  - description: Discover and invoke native page tools across the browser instance.
    name: Browser WebMCP
  - description: Read, write, and manage files on the browser instance.
    name: Browser Filesystem
  - description: Execute and manage processes on the browser instance.
    name: Browser Processes
  - description: Record and manage browser session video replays.
    name: Browser Replays
  - description: Stream logs from the browser instance.
    name: Browser Logs
  - description: >-
      Stream live telemetry events from a browser session, and manage the
      destinations sessions export them to.
    name: Browser Telemetry
  - description: Create, list, retrieve, and delete browser profiles.
    name: Profiles
  - description: Create and manage proxy configurations for routing browser traffic.
    name: Proxies
  - description: Create, list, retrieve, and delete browser extensions.
    name: Extensions
  - description: Create and manage browser pools for acquiring and releasing browsers.
    name: Browser Pools
  - description: Inspect the identity and authorization context for the current request.
    name: Authentication
  - description: >-
      Create and manage auth connections for automated credential capture and
      login.
    name: Managed Auth
  - description: Create and manage credentials for authentication.
    name: Credentials
  - description: Configure external credential providers like 1Password.
    name: Credential Providers
  - description: List applications and versions.
    name: Apps
  - description: Create and manage app deployments and stream deployment events.
    name: Deployments
  - description: Invoke actions and stream or query invocation status and events.
    name: Invocations
  - description: Read and manage organization-level limits.
    name: Organization
  - description: |
      Create and manage projects for resource isolation within an organization.
      When projects are disabled for the organization, project operations return
      `404` with code `projects_disabled`.
    name: Projects
  - description: Create and manage API keys for organization and project-scoped access.
    name: API Keys
  - description: Read audit log records for the authenticated organization.
    name: Audit Logs
  - description: Resolve browser and proxy recommendations for bot-protected sites.
    name: Config Registry
paths:
  /vaults/{id_or_name}/encryption_key:
    parameters:
      - in: path
        name: id_or_name
        required: true
        schema:
          type: string
    get:
      tags:
        - Vaults
      summary: Get a vault's public key for browser-encrypted credential values
      description: >-
        Returns the public key that custom credential collection web apps use to
        encrypt values in the browser. Use this only if you run your own
        credential collection web app and want values encrypted in the browser,
        sent to your backend still encrypted, and forwarded to Kernel's API
        still encrypted. In every other case, including server-side code that
        already holds the plaintext, use value. The page encrypts each value to
        this key, your backend forwards the ciphertext unchanged as
        encrypted_value when creating or updating a credential item in this
        vault, and Kernel decrypts it.
      operationId: getVaultEncryptionKey
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultEncryptionKey'
          description: Vault encryption key
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    VaultEncryptionKey:
      additionalProperties: false
      description: >-
        Public key for encrypted_value on credential fields. Use this only if
        you run your own credential collection web app and want values encrypted
        in the browser, sent to your backend still encrypted, and forwarded to
        Kernel's API still encrypted. In every other case, including server-side
        code that already holds the plaintext, use value. Each vault has its own
        key; a value encrypted for one vault is rejected by every other vault.
        The key is created on first request and stays the same for the vault's
        lifetime, so it may be cached.
      properties:
        alg:
          description: JWE key management algorithm.
          enum:
            - ECDH-ES
          type: string
        enc:
          description: JWE content encryption algorithm.
          enum:
            - A256GCM
          type: string
        jwk:
          $ref: '#/components/schemas/VaultEncryptionPublicJWK'
        kid:
          description: Key ID. Set it as the kid protected header of every encrypted_value.
          type: string
      required:
        - kid
        - alg
        - enc
        - jwk
      type: object
    VaultEncryptionPublicJWK:
      additionalProperties: false
      description: P-256 public key in JWK form.
      properties:
        crv:
          enum:
            - P-256
          type: string
        kty:
          enum:
            - EC
          type: string
        'true':
          description: Base64url-encoded y coordinate.
          type: string
        x:
          description: Base64url-encoded x coordinate.
          type: string
      required:
        - kty
        - crv
        - x
        - true
      type: object
    Error:
      properties:
        code:
          description: Application-specific error code (machine-readable)
          example: bad_request
          type: string
        details:
          description: Additional error details (for multiple errors)
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type: array
        inner_error:
          $ref: '#/components/schemas/ErrorDetail'
        message:
          description: Human-readable error description for debugging
          example: 'Missing required field: app_name'
          type: string
      required:
        - code
        - message
      type: object
    ErrorDetail:
      properties:
        code:
          description: Lower-level error code providing more specific detail
          example: invalid_input
          type: string
        message:
          description: Further detail about the error
          example: Provided version string is not semver compliant
          type: string
      type: object
  responses:
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Unauthorized – missing or invalid authorization token
    NotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Resource not found
    InternalError:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Internal Server Error
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.