Skip to content
← Back to documentation
Technical Reference

HashiCorp Vault

Securely manage secrets and sensitive data with HashiCorp Vault

CategoryDeveloper Tools
Authenticationcustom
Version0.1.0
Published scopes0 published scopes
Last updatedSeptember 19, 2026

Overview

Connect HashiCorp Vault with Flows360

Securely manage secrets and sensitive data with HashiCorp Vault

Use the HashiCorp Vault connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 5 actions and no declared triggers.

Available actions

  • Read Secret
  • Write Secret
  • Delete Secret
  • List Secrets
  • Custom API Call

Available triggers

  • No triggers are declared in this pinned package.

The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.

Technical guide

Technical reference

Package identity

  • Connector: HashiCorp Vault
  • Package: @activepieces/piece-hashi-corp-vault@0.1.0
  • Exact artifact digest: sha256:4ed081a4490a245ce12b42e04e0c8a5600d18506b99696ae663c85b8bd5988ea
  • Runtime: Activepieces-compatible deterministic worker
  • Source: the exact reviewed Activepieces source

Authentication

CUSTOM AUTH. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.

Action contracts

  • Read Secret (read_secret), Read a secret from HashiCorp Vault Classification: read.
  • Write Secret (write_secret), Write a secret to HashiCorp Vault Classification: read.
  • Delete Secret (delete_secret), Delete a secret from HashiCorp Vault Classification: read.
  • List Secrets (list_secrets), List secrets at a path in HashiCorp Vault Classification: read.
  • Custom API Call (custom_api_call), Make a custom API call to a specific endpoint Classification: read.

Trigger contracts

  • No trigger delivery contracts are declared.

Verification

Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Capability summary

Authenticationcustom
Supported objects5
Supported actions5
TriggersNone published

Authentication

Authentication method: custom

Authentication profiles

connection · custom
  • Vault URL Required
  • Authentication Method Required
  • Vault Token Optional · protected credential
  • Role ID Optional
  • Secret ID Optional · protected credential
  • AppRole Mount Path Optional
  • Namespace Optional
  • KV Secrets Engine Version Required

Supported objects

ObjectReadWriteNotes
Read Secret Yes No Read a secret from HashiCorp Vault
Write Secret Yes No Write a secret to HashiCorp Vault
Delete Secret Yes No Delete a secret from HashiCorp Vault
List Secrets Yes No List secrets at a path in HashiCorp Vault
Custom API Call Yes No Make a custom API call to a specific endpoint

Supported actions

Read Secret · Read

Read a secret from HashiCorp Vault

read_secret · Risk: low · Retry: safe

Inputs

  • secretEngine · string · Required, The name of the secrets engine (mount path)
  • secretPath · string · Required, The path to the secret (e.g., myapp/database)
  • version · number · Optional, Version of the secret to read (0 for latest, KV v2 only)
Write Secret · Read

Write a secret to HashiCorp Vault

write_secret · Risk: low · Retry: safe

Inputs

  • secretEngine · string · Required, The name of the secrets engine (mount path)
  • secretPath · string · Required, The path to store the secret (e.g., myapp/database)
  • secretData · object · Required, The secret data to store as JSON
Delete Secret · Read

Delete a secret from HashiCorp Vault

delete_secret · Risk: low · Retry: safe

Inputs

  • secretEngine · string · Required, The name of the secrets engine (mount path)
  • secretPath · string · Required, The path to the secret to delete (e.g., myapp/database)
List Secrets · Read

List secrets at a path in HashiCorp Vault

list_secrets · Risk: low · Retry: safe

Inputs

  • secretEngine · string · Required, The name of the secrets engine (mount path)
  • listPath · string · Optional, The path to list secrets from (e.g., myapp/)
Custom API Call · Read

Make a custom API call to a specific endpoint

custom_api_call · Risk: low · Retry: safe

Inputs

  • url · object · Required
  • method · string · Required
  • headers · object · Optional, Authorization headers are injected automatically from your connection.
  • queryParams · object · Optional, Appended to the URL as ?key=value.
  • body_type · string · Optional
  • body · object · Optional
  • response_is_binary · boolean · Optional, Enable for files like PDFs, images, etc.
  • failsafe · boolean · Optional, On a failed request, output the error instead of failing the step.
  • timeout · number · Optional, Seconds to wait for a response. Empty: up to the flow limit (10 min).
  • followRedirects · boolean · Optional, Follow 3xx redirects instead of returning them as the response.

Setup

Setup

  1. Add the HashiCorp Vault connector to the workflow in the target Flows360 Studio instance.
  2. Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
  3. Provide the connection fields declared by the pinned package:
  • Vault URL (url), required.
  • Authentication Method (authMethod), required.
  • Vault Token (token), optional; stored as a sensitive connection value.
  • Role ID (roleId), optional.
  • Secret ID (secretId), optional; stored as a sensitive connection value.
  • AppRole Mount Path (appRolePath), optional.
  • Namespace (namespace), optional.
  • KV Secrets Engine Version (apiVersion), required.
  1. Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
  2. Test the workflow in the appropriate environment before enabling production scheduling or event delivery.

Limitations

Limitations and operational notes

  • This content describes @activepieces/piece-hashi-corp-vault@0.1.0; provider behaviour can change independently and should be revalidated when the provider or connector version changes.
  • Only the 5 actions and 0 triggers declared by this pinned package are represented here.
  • Tenant credentials and connection values are not stored in the public connector record.
  • Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
  • Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Troubleshooting

Why canu2019t the connector authenticate?

Check the tenant connection in Studio and confirm every required HashiCorp Vault connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.

Why is an action or trigger unavailable?

Confirm that the workflow is using @activepieces/piece-hashi-corp-vault@0.1.0 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.

What should I check after a provider-side change?

Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.