---
title: "Create a new Vault"
method: POST
path: "/vaults"
tags: ["Vaults"]
---

# Create a new Vault

`POST /vaults`

Create a new Vault

## Request body

- Vault — Vault entities are used to configure different Vault connectors. Examples of Vaults are Environment Variables, Hashicorp Vault and AWS Secrets Manager. Configuring a Vault allows referencing the secrets with other entities. For example a certificate entity can store a reference to a certificate and key, stored in a vault, instead of storing the certificate and key within the entity. This allows a proper separation of secrets and configuration and prevents secret sprawl.
  - `config` object, required — The configuration properties for the Vault which can be found on the vaults' documentation page.
  - `created_at` integer, nullable — Unix epoch when the resource was created.
  - `description` string, nullable — The description of the Vault entity.
  - `id` string, nullable
  - `name` string, required — The name of the Vault that's going to be added. Currently, the Vault implementation must be installed in every Kong instance.
  - `prefix` string, required — The unique prefix (or identifier) for this Vault configuration. The prefix is used to load the right Vault configuration and implementation when referencing secrets with the other entities.
  - `tags` string[] — An optional set of strings associated with the Vault for grouping and filtering.
  - `updated_at` integer, nullable — Unix epoch when the resource was last updated.

## Response `201`

Successfully created Vault

- Vault — Vault entities are used to configure different Vault connectors. Examples of Vaults are Environment Variables, Hashicorp Vault and AWS Secrets Manager. Configuring a Vault allows referencing the secrets with other entities. For example a certificate entity can store a reference to a certificate and key, stored in a vault, instead of storing the certificate and key within the entity. This allows a proper separation of secrets and configuration and prevents secret sprawl.
  - `config` object, required — The configuration properties for the Vault which can be found on the vaults' documentation page.
  - `created_at` integer, nullable — Unix epoch when the resource was created.
  - `description` string, nullable — The description of the Vault entity.
  - `id` string, nullable
  - `name` string, required — The name of the Vault that's going to be added. Currently, the Vault implementation must be installed in every Kong instance.
  - `prefix` string, required — The unique prefix (or identifier) for this Vault configuration. The prefix is used to load the right Vault configuration and implementation when referencing secrets with the other entities.
  - `tags` string[] — An optional set of strings associated with the Vault for grouping and filtering.
  - `updated_at` integer, nullable — Unix epoch when the resource was last updated.

## Other responses

- `401` — Unauthorized

## Changes

> 7 revisions in range; 1 not diffed.

- **2025-04-04** `e07a25288f1f` — 2 breaking, 6 info
  - the response property `created_at` became nullable for the status `201`
  - the response property `updated_at` became nullable for the status `201`
  - the request optional property `created_at` became not read-only
  - the request optional property `updated_at` became not read-only
  - …4 more
- **2024-11-26** `99e71588eb61` — 5 breaking, 7 info
  - the request property `config` became required
  - the request property `name` became required
  - the request property `prefix` became required
  - the response property `description` became nullable for the status `201`
  - …8 more

[Change history](https://skmtc.dev/kong/apis/kong-enterprise-admin-api/changes/vaults/post.md)

---

[API](https://skmtc.dev/kong/apis/kong-enterprise-admin-api.md) · [All operations](https://skmtc.dev/kong/apis/kong-enterprise-admin-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/kong/kong-enterprise-admin-api/revisions/daef3e27adf6/schema)
