pentest api-security vault appsec
Vault API — Endpoint Inventory
Working inventory of known Vault API endpoints. Do not invent endpoints — populate only from OpenAPI/Swagger, architecture docs, or observed traffic.
Endpoint Table
| Method | Endpoint | Purpose | Auth Required | Role/Team | Object | Environment | Tested | Notes |
|---|---|---|---|---|---|---|---|---|
| [ ] |
To Confirm
No endpoints documented yet. Collect during kickoff or discovery phase.
Sources to check:
- OpenAPI / Swagger (see Vault API - Kickoff Questions)
- Proxy traffic (Burp)
- Architecture documentation