Create a Vault Transit provider with the given options.
Build a Vault API URL for the transit engine.
Common headers for Vault API requests.
List all keys, optionally filtered by usage or enabled state.
Optional_filters: { usage?: string; enabled?: boolean }Retrieve metadata for a specific key by ID.
Create a new key with the given algorithm and usage.
Optional_metadata: Record<string, string>Enable a previously disabled key.
Disable a key so it cannot be used for operations.
Schedule a key for deletion after a pending window.
Optional_pendingWindowDays: numberEncrypt plaintext using a managed key.
Optional_context: Record<string, string>Decrypt ciphertext using a managed key.
Optional_context: Record<string, string>Sign data using a managed signing key.
Optional_algorithm: string
HashiCorp Vault Transit secrets engine adapter.
Uses the Vault HTTP API to provide the unified KmsProvider interface. No additional SDK dependency is required — uses native
fetch.Example