API Reference

Delinea Credentials Cache provides a RESTful API for authentication, credential retrieval, and cache management. The same endpoints are available whether the service is installed on Windows, installed on Linux, or deployed as a Docker container. Swagger UI is published as part of the package, so you can explore and test each endpoint directly from a browser.

The API has three endpoints:

Accessing Swagger UI

Swagger UI is an interactive web page that documents the API and lets you execute test requests without writing code. Use it to validate an installation, troubleshoot API issues, and become familiar with the API before integrating it into your applications.

Open the following URL in a browser:

https://{ServerName}/{installedFolderDirectory}/swagger/index.html

Replace {ServerName} with your server name and {installedFolderDirectory} with the IIS application alias or proxy path of your installation (for example DelineaCredCache). For a Docker deployment, use the mapped host port instead, for example http://{hostname}:8083/swagger.

Confirm:

  • The Swagger page loads.

  • API endpoints are visible.

  • An Authorize button exists.

If Swagger does not load, check the hosting logs. On Windows, open Event Viewer > Windows Logs > Application; errors there commonly indicate an IIS binding or path mismatch or an ASP.NET Core hosting issue. On Linux, run sudo journalctl -u credcache.service for the application output and check the Apache HTTP Server error log (/var/log/apache2/error.log on Ubuntu, /var/log/httpd/error_log on RHEL) for proxy errors. On Docker, run docker logs delinea-credential-cache. See also Troubleshooting.

Swagger Authorization

Before using the protected endpoints, you must authorize with a Bearer token obtained from the Token Generation endpoint.

  1. Open Swagger UI.

  2. Select Authorize.

  3. Enter:

    Bearer <access_token>

  4. Select Authorize, then select Close.

Endpoints

Token Generation

The Token Generation endpoint is the entry point for all API interactions. It accepts your vault username, password, base URL, and optional domain, authenticates with the vault, and returns a Bearer token that you use to authorize subsequent calls.

Endpoint

POST /api/token

Authorization

Not required

Request Content-Type

application/x-www-form-urlencoded

Request Parameters

Name Type Required Description
Username string Yes Vault username (Secret Server application account or Delinea Platform client ID)
Password string Yes Vault user password (or Delinea Platform client secret)
BaseUrl string Yes Base URL of Secret Server or of the Delinea Platform tenant
Domain string No Domain name (if applicable)

Expected Result

  • 200 OK with the token in the response body

Example (PowerShell)

Copy
$body = @{
    Username = "<username>"
    Password = "<password>"
    BaseUrl  = "https://<secret-server-host>/SecretServer"
    Domain   = "<domain>"   # optional
}

$response = Invoke-RestMethod `
    -Method Post `
    -Uri "https://localhost/DelineaCredCache/api/token" `
    -ContentType "application/x-www-form-urlencoded" `
    -Body $body

$response

API Credential by ID

The API Credential by ID endpoint is the core function of Delinea Credentials Cache. When an application needs a secret, it calls this endpoint with the Secret ID. The cache fetches the secret from the vault and stores it locally for the configured time-to-live (CredCacheExpirationInMinutes, 10 minutes by default; see Configuring Delinea Credentials Cache). Subsequent requests for the same secret within that period are served from the cache, which reduces API calls to the vault and improves application performance.

Endpoint

GET /api/credential/{id}

Authorization

Required (Bearer token)

Path Parameters

Name Type Required Description
id int Yes Secret ID in the vault

Query Parameters

Name Type Required Description
autoComment string No Optional audit or log comment

Sample Request

Copy
GET /api/credential/1234?autoComment=Fetched+by+App
Authorization: Bearer <access_token>

Expected Result

  • 200 OK – Credential retrieved successfully

Refresh Secret on Change Event

The Refresh Secret on Change Event endpoint keeps cached credentials synchronized with the vault when passwords or other secret values change. Rather than waiting for the cache entry to expire, an Event Pipeline in Secret Server or the Delinea Platform runs a PowerShell script that calls this endpoint with the changed Secret ID. The endpoint validates the request, fetches the updated secret from the vault, and updates or inserts it in the local cache immediately. You control which secrets trigger a refresh by adding secret filters to the Event Pipeline policy. See Event-Driven Secret Refresh.

Endpoint

POST /api/secretchanged

Authorization

Required (Bearer token)

Request Content-Type

application/json

Request Body

Copy
{
  "secretId": "1234"
}

Request Parameters

Name Type Required Description
secretId string Yes Secret ID that changed

Sample Request

Copy
POST /api/secretchanged
Authorization: Bearer <access_token>
Content-Type: application/json

{
  "secretId": "1234"
}

Expected Result

  • 202 Accepted

To confirm the refresh occurred: enable logging (see Configuring Delinea Credentials Cache) and verify that the latest log entries show the secret retrieval and cache update for the specified Secret ID, as described in Verifying the Deployment.