{"_id":"@dynatrace-sdk/client-credential-vault","name":"@dynatrace-sdk/client-credential-vault","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@dynatrace-sdk/client-credential-vault","version":"1.0.0","dependencies":{"@dynatrace-sdk/http-client":"^1.5.1","@dynatrace-sdk/shared-errors":"^1.0.2"},"license":"Apache-2.0","main":"./cjs/index.js","module":"./esm/index.js","types":"./types/index.d.ts","_id":"@dynatrace-sdk/client-credential-vault@1.0.0","description":"[![npm](https://img.shields.io/badge/npm-v1.0.0-blue)](https://www.npmjs.com/package/@dynatrace-sdk/client-credential-vault/v/1.0.0) [![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)","_integrity":"sha512-4QuemU+CE+i5g3v/5KzjZhgbfBfFauEBAssepa58OQO1MqLYWrp8gMh82GCfiWtCOxp3TZ+SIZPAPqHUTAcvtg==","_resolved":"/tmp/npm-publish-@dynatrace-sdk-client-credential-vault-1.0.0-zxlFDR/dynatrace-sdk-client-credential-vault-1.0.0.tgz","_from":"file:dynatrace-sdk-client-credential-vault-1.0.0.tgz","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-4QuemU+CE+i5g3v/5KzjZhgbfBfFauEBAssepa58OQO1MqLYWrp8gMh82GCfiWtCOxp3TZ+SIZPAPqHUTAcvtg==","shasum":"d1c2ea1f7554af128ac318fd3bb9fdf5f32937c7","tarball":"https://registry.npmjs.org/@dynatrace-sdk/client-credential-vault/-/client-credential-vault-1.0.0.tgz","fileCount":8,"unpackedSize":197454,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCeuncWUpgqKf30fIM2palL2s3etcksrOGW97jJQtuucwIgNWwqKjTswx4B5Ewp9XZ5jgDk1dxVqAw4NtM1IpeS5wk="}]},"_npmUser":{"name":"dynatrace-nodejs","email":"nodejs@dynatrace.com"},"directories":{},"maintainers":[{"name":"dynatrace-nodejs","email":"nodejs@dynatrace.com"},{"name":"stefan.wolfsteiner.dynatrace","email":"stefan.wolfsteiner@dynatrace.com"},{"name":"wasserb","email":"Stefan.wasserbauer@dynatrace.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/client-credential-vault_1.0.0_1784286028075_0.0010558793494979124"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-17T11:00:27.900Z","1.0.0":"2026-07-17T11:00:28.247Z","modified":"2026-07-17T11:00:28.537Z"},"maintainers":[{"name":"dynatrace-nodejs","email":"nodejs@dynatrace.com"},{"name":"stefan.wolfsteiner.dynatrace","email":"stefan.wolfsteiner@dynatrace.com"},{"name":"wasserb","email":"Stefan.wasserbauer@dynatrace.com"}],"description":"[![npm](https://img.shields.io/badge/npm-v1.0.0-blue)](https://www.npmjs.com/package/@dynatrace-sdk/client-credential-vault/v/1.0.0) [![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)","license":"Apache-2.0","readme":"# @dynatrace-sdk/client-credential-vault\n\n[![npm](https://img.shields.io/badge/npm-v1.0.0-blue)](https://www.npmjs.com/package/@dynatrace-sdk/client-credential-vault/v/1.0.0)\n[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n\nManage credential entries of username/password, certificate, and token types, with support for external vault integrations.\n\nTo authorize, use a valid OAuth token.\n\nNotes about compatibility:\n* Operations marked as early adopter or preview may be changed in non-compatible ways, although we try to avoid this.\n* We may add new enum constants without incrementing the API version; thus, clients need to handle unknown enum constants gracefully.\n\n\n## Installation\n\n```bash\nnpm install @dynatrace-sdk/client-credential-vault\n```\n\n\n## Getting help\n\n- Visit [SDK for Typescript](https://developer.dynatrace.com/reference/sdks/) guide in the [Dynatrace Developer](https://developer.dynatrace.com/)\n- Ask a question in the [Dynatrace Community](https://community.dynatrace.com/)\n\n\n## License\n\nThis SDK is distributed under the [Apache License, Version 2.0](http://www.apache.org/licenses/LICENSE-2.0), see LICENSE for more information.\n\n\n# API reference\n\nFull API reference for the latest version of the SDK is also available at the [Dynatrace Developer](https://developer.dynatrace.com/reference/sdks/client-credential-vault/).\n\n## credentialVaultEntriesClient\n\n```js\nimport { credentialVaultEntriesClient } from '@dynatrace-sdk/client-credential-vault';\n```\n\n\n<a name=\"createcredentialvaultentry\"></a>\n### createCredentialVaultEntry\n\n<div class=\"padding-bottom--md\">\n<strong>credentialVaultEntriesClient.createCredentialVaultEntry(config): Promise&lt;<a href=\"#credentialsid\">CredentialsId</a>&gt;</strong>\n\n<div class=\"padding-left--md\">\n\nCreates a new credential entry. | maturity=EARLY_ADOPTER\n\n**Required scope:** credential-vault:entries:write\n\nThe body must not provide an ID. An ID is assigned automatically by the Dynatrace server.\n\n\n\n</div>\n\n\n#### Parameters\n\n| Name | Type |\n| --- | --- |\n|config.body<sup>*required</sup>|<a href=\"#credentials\" target=\"_blank\" rel=\"noopener noreferrer\">Credentials</a>|\n\n\n\n\n#### Returns\n\n| Return type | Status code | Description |\n|---|---|---|\n|[CredentialsId](#credentialsid)|201|Success. The new credential entry has been created. The response contains the ID of the entry.|\n\n\n#### Throws\n\n| Error Type | Error Message |\n|---|---|\n|ErrorResponseEnvelopeError|Client side error. &#124; Server side error.|\n\n\n<details>\n<summary>\nCode example\n</summary>\n\n```ts\nimport { credentialVaultEntriesClient } from \"@dynatrace-sdk/client-credential-vault\";\n\nconst data =\n  await credentialVaultEntriesClient.createCredentialVaultEntry(\n    {\n      body: {\n        name: \"...\",\n        scopes: [\"APP_ENGINE\"],\n        type: \"AWS_MONITORING_KEY_BASED\",\n      },\n    },\n  );\n```\n\n</details>\n\n\n\n</div>\n\n\n<a name=\"deletecredentialvaultentry\"></a>\n### deleteCredentialVaultEntry\n\n<div class=\"padding-bottom--md\">\n<strong>credentialVaultEntriesClient.deleteCredentialVaultEntry(config): Promise&lt;void&gt;</strong>\n\n<div class=\"padding-left--md\">\n\nDeletes the specified credential entry. | maturity=EARLY_ADOPTER\n\n**Required scope:** credential-vault:entries:admin\n\nProvide the credential ID in the path.\n\n\n\n</div>\n\n\n#### Parameters\n\n| Name | Type | Description |\n| --- | --- | --- |\n|config.entryId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credential entry to be deleted.|\n\n\n\n\n#### Returns\n\n| Return type | Status code | Description |\n|---|---|---|\n|void|204|Success. The credential entry has been deleted. The response doesn&apos;t have a body.|\n\n\n#### Throws\n\n| Error Type | Error Message |\n|---|---|\n|ErrorResponseEnvelopeError|Client side error. &#124; Server side error.|\n\n\n<details>\n<summary>\nCode example\n</summary>\n\n```ts\nimport { credentialVaultEntriesClient } from \"@dynatrace-sdk/client-credential-vault\";\n\nconst data =\n  await credentialVaultEntriesClient.deleteCredentialVaultEntry(\n    { entryId: \"...\" },\n  );\n```\n\n</details>\n\n\n\n</div>\n\n\n<a name=\"getcredentialvaultentry\"></a>\n### getCredentialVaultEntry\n\n<div class=\"padding-bottom--md\">\n<strong>credentialVaultEntriesClient.getCredentialVaultEntry(config): Promise&lt;<a href=\"#credentialsresponseelement\">CredentialsResponseElement</a>&gt;</strong>\n\n<div class=\"padding-left--md\">\n\nGets the metadata of the specified credential entry. | maturity=EARLY_ADOPTER\n\n**Required scope:** credential-vault:entries:read\n\nThe credential entry itself (e.g. username/certificate and password) is not included in the response.\n\n\n\n</div>\n\n\n#### Parameters\n\n| Name | Type | Description |\n| --- | --- | --- |\n|config.entryId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the required credential entry.|\n\n\n\n\n#### Returns\n\n| Return type | Status code | Description |\n|---|---|---|\n|[CredentialsResponseElement](#credentialsresponseelement)|200|Success. The response contains the metadata of the credential entry.|\n\n\n#### Throws\n\n| Error Type | Error Message |\n|---|---|\n|ErrorResponseEnvelopeError|Client side error. &#124; Server side error.|\n\n\n<details>\n<summary>\nCode example\n</summary>\n\n```ts\nimport { credentialVaultEntriesClient } from \"@dynatrace-sdk/client-credential-vault\";\n\nconst data =\n  await credentialVaultEntriesClient.getCredentialVaultEntry(\n    { entryId: \"...\" },\n  );\n```\n\n</details>\n\n\n\n</div>\n\n\n<a name=\"listcredentialvaultentries\"></a>\n### listCredentialVaultEntries\n\n<div class=\"padding-bottom--md\">\n<strong>credentialVaultEntriesClient.listCredentialVaultEntries(config): Promise&lt;<a href=\"#credentialslist\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialsList</a>&gt;</strong>\n\n<div class=\"padding-left--md\">\n\nLists all credential entries in your environment. | maturity=EARLY_ADOPTER\n\n**Required scope:** credential-vault:entries:read\n\nThe credential entry itself (username/certificate and password) is not included in the response.\n\n\n\n</div>\n\n\n#### Parameters\n\n| Name | Type | Description |\n| --- | --- | --- |\n|config.name|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Filters the result by name. Enclose the value in quotation marks to match the whole phrase. Case-insensitive.|\n|config.pageKey|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|<p>The cursor for the next page of results. You can find it in the <strong>nextPageKey</strong> field of the previous response.</p> <p>The first page is always returned if you don't specify the <strong>page-key</strong> query parameter.</p> <p>When the <strong>page-key</strong> is set to obtain subsequent pages, you must omit all other query parameters.</p> |\n|config.pageSize|[number](https://developer.mozilla.org/en-US/docs/Glossary/Number)|<p>The amount of credential vault entries in a single response payload.</p> <p>The maximal allowed page size is 500.</p> <p>If not set, 100 is used.</p> |\n|config.scope|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Filters the result by the specified scope.|\n|config.type|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|Filters the result by the specified credential type.|\n|config.user|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Filters the result to credentials accessible to the specified user (those they own or those shared with everyone).|\n\n\n\n\n#### Returns\n\n| Return type | Status code | Description |\n|---|---|---|\n|[CredentialsList](#credentialslist)|200|Success|\n\n\n#### Throws\n\n| Error Type | Error Message |\n|---|---|\n|ErrorResponseEnvelopeError|Client side error. &#124; Server side error.|\n\n\n<details>\n<summary>\nCode example\n</summary>\n\n```ts\nimport { credentialVaultEntriesClient } from \"@dynatrace-sdk/client-credential-vault\";\n\nconst data =\n  await credentialVaultEntriesClient.listCredentialVaultEntries();\n```\n\n</details>\n\n\n\n</div>\n\n\n<a name=\"updatecredentialvaultentry\"></a>\n### updateCredentialVaultEntry\n\n<div class=\"padding-bottom--md\">\n<strong>credentialVaultEntriesClient.updateCredentialVaultEntry(config): Promise&lt;void&gt;</strong>\n\n<div class=\"padding-left--md\">\n\nUpdates the specified credential entry. | maturity=EARLY_ADOPTER\n\n**Required scope:** credential-vault:entries:admin\n\nThe body must not provide an ID. The ID should be provided in the path.\n\n\n\n</div>\n\n\n#### Parameters\n\n| Name | Type | Description |\n| --- | --- | --- |\n|config.body<sup>*required</sup>|<a href=\"#credentials\">Credentials</a>||\n|config.entryId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credential entry to be updated.|\n\n\n\n\n#### Returns\n\n| Return type | Status code | Description |\n|---|---|---|\n|void|204|Success. The credential entry has been updated. The response doesn&apos;t have a body.|\n\n\n#### Throws\n\n| Error Type | Error Message |\n|---|---|\n|ErrorResponseEnvelopeError|Client side error. &#124; Server side error.|\n\n\n<details>\n<summary>\nCode example\n</summary>\n\n```ts\nimport { credentialVaultEntriesClient } from \"@dynatrace-sdk/client-credential-vault\";\n\nconst data =\n  await credentialVaultEntriesClient.updateCredentialVaultEntry(\n    {\n      entryId: \"...\",\n      body: {\n        name: \"...\",\n        scopes: [\"APP_ENGINE\"],\n        type: \"AWS_MONITORING_KEY_BASED\",\n      },\n    },\n  );\n```\n\n</details>\n\n\n\n</div>\n\n## Types\n\n### AWSKeyBasedCredentialsDto\n\nA credentials set of the `AWS_MONITORING_KEY_BASED` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accessKeyID<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Access Key ID  of the credentials set.|\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|awsPartition<sup>*required</sup>|\"CHINA\" &#124; \"DEFAULT\" &#124; \"US_GOV\"|AWS partition of the credential.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|secretKey<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Secret access key of the credential.|\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### AWSRoleBasedCredentials\n\nA credentials set of the `AWS_MONITORING_ROLE_BASED` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accountID<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Amazon account ID of the credential.|\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|iamRole<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The IAM role name of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### AzureClientSecret\n\nSynchronization credentials with Azure Key Vault using client secret authentication method\n\n| Name | Type | Description |\n| --- | --- | --- |\n|clientId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Client (application) ID of Azure application in Azure Active Directory which has permission to access secrets in Azure Key Vault.|\n|clientSecret|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Client secret generated for Azure application in Azure Active Directory used for proving identity when requesting a token used later for accessing secrets in Azure Key Vault.|\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tenantId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Tenant (directory) ID of Azure application in Azure Active Directory which has permission to access secrets in Azure Key Vault.|\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### AzureClientSecretConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|clientId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|clientSecret|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tenantId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### CertificateCredentials\n\nA credentials set of the `CERTIFICATE` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|certificate<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|String containing the certificate file bytes encoded in Base64 without carriage return.|\n|certificateFormat<sup>*required</sup>|\"UNKNOWN\" &#124; \"PEM\" &#124; \"PKCS12\"|The certificate format. Use <code>PEM</code> for PEM certificates and <code>PKCS12</code> for PFX and P12 certificates.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|password<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The password of the credential encoded in Base64. Must be empty for <code>PEM</code> certificates.|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### ConstraintViolation\n\nInformation about a single constraint violation.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|context|<a href=\"#constraintviolationcontext\">ConstraintViolationContext</a>|<p>Structured context of the constraint violation. Well known keys that <strong>can</strong> be present are:</p> <ul> <li><code>reason</code> -&gt; Additional reasoning behind the occurred violation.</li> <li><code>pipeline</code> -&gt; Pipeline related to the violation.</li> <li><code>endpoint</code> -&gt; Endpoint related to the violation.</li> <li><code>stage</code> -&gt; Stage related to the violation.</li> <li><code>processor</code> -&gt; Processor related to the violation.</li> <li><code>routingRule</code> -&gt; Routing rule related to the violation.</li> </ul> |\n|message<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Description of the constraint violation.|\n\n### ConstraintViolationContext\n\nStructured context of the constraint violation.\nWell known keys that **can** be present are:\n* `reason` -&gt; Additional reasoning behind the occurred violation.\n* `pipeline` -&gt; Pipeline related to the violation.\n* `endpoint` -&gt; Endpoint related to the violation.\n* `stage` -&gt; Stage related to the violation.\n* `processor` -&gt; Processor related to the violation.\n* `routingRule` -&gt; Routing rule related to the violation.\n\n**type**: Record&lt;string, string&gt;\n\n### ConstraintViolationDetails\n\nList of encountered constraint violations.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|constraintViolations<sup>*required</sup>|Array&lt;<a href=\"#constraintviolation\" target=\"_blank\" rel=\"noopener noreferrer\">ConstraintViolation</a>&gt;|List of encountered constraint violations.|\n|type<sup>*required</sup>|\"constraintViolation\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>constraintViolation</code> -&gt; ConstraintViolationDetails</li> </ul> |\n\n### CredentialAccessData\n\nThe set of entities allowed to use the credential.\n\n| Name | Type |\n| --- | --- |\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|\n|type|\"APPLICATION\" &#124; \"UNKNOWN\" &#124; \"USER\"|\n\n### CredentialUsageHandler\n\nKeeps information about credential&apos;s usage.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|count|[number](https://developer.mozilla.org/en-US/docs/Glossary/Number)|The number of uses.|\n|type|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Type of usage.|\n\n### Credentials\n\nA set of credentials for synthetic monitors.\n\nThe actual set of fields depends on the type of credentials. Find the list of actual objects in the description of the **type** field or see [Credential vault API - JSON models](https://dt-url.net/2sa3sen).\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### CredentialsId\n\nA short representation of the credentials set.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|id<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n\n### CredentialsList\n\nA list of credentials sets for Synthetic monitors.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|credentials<sup>*required</sup>|Array&lt;<a href=\"#credentialsresponseelement\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialsResponseElement</a>&gt;|A list of credentials sets for Synthetic monitors.|\n|nextPageKey|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|pageSize|[number](https://developer.mozilla.org/en-US/docs/Glossary/Number)||\n|totalCount|[number](https://developer.mozilla.org/en-US/docs/Glossary/Number)||\n\n### CredentialsResponseElement\n\nMetadata of the credentials set.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow access without app context, for example, from ad hoc functions in Workflows (requires the APP_ENGINE scope).|\n|allowedEntities<sup>*required</sup>|Array&lt;<a href=\"#credentialaccessdata\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|credentialUsageSummary<sup>*required</sup>|Array&lt;<a href=\"#credentialusagehandler\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialUsageHandler</a>&gt;|The list contains summary data related to the use of credentials.|\n|description<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|externalVault|<a href=\"#externalvaultconfig\">ExternalVaultConfig</a>|Configuration for external vault synchronization for username and password credentials.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|owner<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The owner of the credential (user for which used API token was created).|\n|ownerAccessOnly<sup>*required</sup>|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Flag indicating that this credential is visible only to the owner.|\n|scope|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|The set of scopes of the credentials set.|\n|type<sup>*required</sup>|\"UNKNOWN\" &#124; \"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|The type of the credentials set.|\n\n### CyberArkAllowedLocationConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accountName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|applicationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|folderName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|safeName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### CyberArkAllowedLocationDto\n\nSynchronization credentials with CyberArk Vault using allowed machines (location) authentication method.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accountName<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Account name that stores the username and password to retrieve and synchronize with the Dynatrace Credential Vault: This is NOT the name of the account logged into the CyberArk Central Credential Provider.|\n|applicationId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Application ID connected to CyberArk Vault.|\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|\\[Recommended] Certificate used for authentication to CyberArk application. ID of certificate credential saved in Dynatrace CV.|\n|folderName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|\\[Optional] Folder name where credentials in CyberArk Vault are stored. Default folder name is 'Root'.|\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|safeName<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Safe name connected to CyberArk Vault.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### CyberArkUsernamePassword\n\nSynchronization credentials with CyberArk Vault using username password authentication method.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accountName<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Account name that stores the username and password to retrieve and synchronize with the Dynatrace Credential Vault: This is NOT the name of the account logged into the CyberArk Central Credential Provider.|\n|applicationId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Application ID connected to CyberArk Vault.|\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|\\[Recommended] Certificate used for authentication to CyberArk application. ID of certificate credential saved in Dynatrace CV.|\n|folderName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|\\[Optional] Folder name where credentials in CyberArk Vault are stored. Default folder name is 'Root'.|\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|safeName<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Safe name connected to CyberArk Vault.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernamePasswordForCPM<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Dynatrace credential ID of the username-password pair used for authentication to the CyberArk Central Credential Provider|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### CyberArkUsernamePasswordConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|accountName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|applicationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|folderName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|safeName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernamePasswordForCPM|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### ErrorResponse\n\nBasic information of the encountered error.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|code<sup>*required</sup>|[number](https://developer.mozilla.org/en-US/docs/Glossary/Number)|The returned HTTP status code.|\n|details|<a href=\"#errorresponsedetails\" target=\"_blank\" rel=\"noopener noreferrer\">ErrorResponseDetails</a>|Detailed information of the error.|\n|message<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Description of the encountered error.|\n\n### ErrorResponseDetails\n\nDetailed information of the error.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|type<sup>*required</sup>|\"constraintViolation\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>constraintViolation</code> -&gt; ConstraintViolationDetails</li> </ul> |\n\n### ErrorResponseEnvelope\n\nEncloses the encountered error.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|error<sup>*required</sup>|<a href=\"#errorresponse\">ErrorResponse</a>|Basic information of the encountered error.|\n\n### ExternalVault\n\nInformation for synchronization credentials with external vault\n\n| Name | Type | Description |\n| --- | --- | --- |\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### ExternalVaultConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### HashicorpApprole\n\nSynchronization credentials with HashiCorp Vault using appRole authentication method\n\n| Name | Type | Description |\n| --- | --- | --- |\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|pathToCredentials<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Path to folder where credentials in HashiCorp Vault are stored.|\n|roleId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Role ID is similar to username when you want to authenticate in HashiCorp Vault using AppRole.|\n|secretId<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Secret ID is similar to password when you want to authenticate in HashiCorp Vault using AppRole. ID of token representing secret ID saved in Dynatrace CV.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultNamespace<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Vault namespace in HashiCorp Vault. It is an information you set as environmental variable VAULT_NAMESPACE if you are accessing HashiCorp Vault from command line.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### HashicorpApproleConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|pathToCredentials|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|roleId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|secretId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultNamespace|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### HashicorpCertificate\n\nSynchronization credentials with HashiCorp Vault using certificate authentication method\n\n| Name | Type | Description |\n| --- | --- | --- |\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|ID of certificate saved in Dynatrace CV. Using this certificate you can authenticate to your HashiCorp Vault.|\n|locationForSynchronizationId|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Id of a location used by the synchronizing monitor|\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where password is stored.|\n|pathToCredentials|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Path to folder where credentials in HashiCorp Vault are stored.|\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApprole</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificate</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecret</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePassword</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationDto</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where token is stored.|\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the secret saved in external vault where username is stored.|\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|External vault URL.|\n\n### HashicorpCertificateConfig\n\nConfiguration for external vault synchronization for username and password credentials.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|certificate|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|credentialsUsedForExternalSynchronization|Array&lt;[string](https://developer.mozilla.org/en-US/docs/Glossary/String)&gt;||\n|passwordSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|pathToCredentials|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|sourceAuthMethod|\"AZURE_KEY_VAULT_CLIENT_SECRET\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD\" &#124; \"HASHICORP_VAULT_APPROLE\" &#124; \"HASHICORP_VAULT_CERTIFICATE\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>HASHICORP_VAULT_APPROLE</code> -&gt; HashicorpApproleConfig</li> <li><code>HASHICORP_VAULT_CERTIFICATE</code> -&gt; HashicorpCertificateConfig</li> <li><code>AZURE_KEY_VAULT_CLIENT_SECRET</code> -&gt; AzureClientSecretConfig</li> <li><code>CYBERARK_VAULT_USERNAME_PASSWORD</code> -&gt; CyberArkUsernamePasswordConfig</li> <li><code>CYBERARK_VAULT_ALLOWED_LOCATION</code> -&gt; CyberArkAllowedLocationConfig</li> </ul> |\n|tokenSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|type|\"AZURE_CERTIFICATE_MODEL\" &#124; \"AZURE_CLIENT_SECRET_MODEL\" &#124; \"CYBERARK_VAULT_ALLOWED_LOCATION_MODEL\" &#124; \"CYBERARK_VAULT_USERNAME_PASSWORD_MODEL\" &#124; \"HASHICORP_APPROLE_MODEL\" &#124; \"HASHICORP_CERTIFICATE_MODEL\"||\n|usernameSecretName|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n|vaultUrl|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)||\n\n### PublicCertificateCredentials\n\nA credentials set of the `PUBLIC_CERTIFICATE` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|certificate<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The certificate in the string format.|\n|certificateFormat<sup>*required</sup>|\"UNKNOWN\" &#124; \"PEM\" &#124; \"PKCS12\"|The certificate format.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|password<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The password of the credential (not supported).|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### SNMPV3Credentials\n\nA credentials set of the `SNMPV3` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|authenticationPassword|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The authentication password in the string format (should not be empty for AUTH_PRIV and AUTH_NO_PRIV security levels)|\n|authenticationProtocol|\"MD5\" &#124; \"SHA\" &#124; \"SHA224\" &#124; \"SHA256\" &#124; \"SHA384\" &#124; \"SHA512\"|The authentication protocol, supported protocols: MD5, SHA, SHA224, SHA256, SHA384, SHA512|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|privacyPassword|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The privacy password in the string format (should not be empty for AUTH_PRIV security level)|\n|privacyProtocol|\"AES\" &#124; \"AES192\" &#124; \"AES192C\" &#124; \"AES256\" &#124; \"AES256C\" &#124; \"DES\"|The privacy protocol|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|securityLevel<sup>*required</sup>|\"AUTH_NO_PRIV\" &#124; \"AUTH_PRIV\" &#124; \"NO_AUTH_NO_PRIV\"|The security level, supported levels: AUTH_PRIV, NO_AUTH_NO_PRIV, AUTH_NO_PRIV|\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n|username<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|User name value|\n\n### TokenCredentials\n\nA credentials set of the `TOKEN` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|externalVault|<a href=\"#externalvault\">ExternalVault</a>|Information for synchronization credentials with external vault|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|token|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|Token in the string format.|\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n\n### UserPasswordCredentials\n\nA credentials set of the `USERNAME_PASSWORD` type.\n\n| Name | Type | Description |\n| --- | --- | --- |\n|allowContextlessRequests|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|Allow ad-hoc functions to access the credential details (requires the APP_ENGINE scope).|\n|allowedEntities|Array&lt;<a href=\"#credentialaccessdata\" target=\"_blank\" rel=\"noopener noreferrer\">CredentialAccessData</a>&gt;|The set of entities allowed to use the credential.|\n|description|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|A short description of the credentials set.|\n|externalVault|<a href=\"#externalvault\">ExternalVault</a>|Information for synchronization credentials with external vault|\n|id|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The ID of the credentials set.|\n|name<sup>*required</sup>|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The name of the credentials set.|\n|ownerAccessOnly|[boolean](https://developer.mozilla.org/en-US/docs/Glossary/Boolean)|The credentials set is available to every user (<code>false</code>) or to owner only (<code>true</code>).|\n|password|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The password of the credential.|\n|~~scope~~<sup>**DEPRECATED**</sup>|\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"|The scope of the credentials set.|\n|scopes<sup>*required</sup>|Array&lt;\"APP_ENGINE\" &#124; \"EXTENSION\" &#124; \"EXTENSION_AUTHENTICATION\" &#124; \"SYNTHETIC\"&gt;|<p>The set of scopes of the credentials set.</p> <p>Limitations: <code>CredentialsScope.APP_ENGINE</code> is only available on the new Dynatrace SaaS platform - it's not available on managed or non-Grail SaaS environments.</p> |\n|type<sup>*required</sup>|\"AWS_MONITORING_KEY_BASED\" &#124; \"AWS_MONITORING_ROLE_BASED\" &#124; \"CERTIFICATE\" &#124; \"PUBLIC_CERTIFICATE\" &#124; \"SNMPV3\" &#124; \"TOKEN\" &#124; \"USERNAME_PASSWORD\"|<p>Defines the actual set of fields depending on the value. See one of the following objects:</p> <ul> <li><code>CERTIFICATE</code> -&gt; CertificateCredentials</li> <li><code>PUBLIC_CERTIFICATE</code> -&gt; PublicCertificateCredentials</li> <li><code>USERNAME_PASSWORD</code> -&gt; UserPasswordCredentials</li> <li><code>TOKEN</code> -&gt; TokenCredentials</li> <li><code>SNMPV3</code> -&gt; SNMPV3Credentials</li> <li><code>AWS_MONITORING_KEY_BASED</code> -&gt; AWSKeyBasedCredentialsDto</li> <li><code>AWS_MONITORING_ROLE_BASED</code> -&gt; AWSRoleBasedCredentials</li> </ul> |\n|user|[string](https://developer.mozilla.org/en-US/docs/Glossary/String)|The username of the credentials set.|\n\n## Enums\n\n<a name=\"credentialaccessdatatype\"></a>\n### ~~CredentialAccessDataType~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\n\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`Application` | `Unknown` | `User`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialsresponseelementscope\"></a>\n### ~~CredentialsResponseElementScope~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nThe scope of the credentials set.\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`AppEngine` | `Extension` | `ExtensionAuthentication` | `Synthetic`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialsresponseelementscopesitem\"></a>\n### ~~CredentialsResponseElementScopesItem~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nThe set of scopes of the credentials set.\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`AppEngine` | `Extension` | `ExtensionAuthentication` | `Synthetic`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialsresponseelementtype\"></a>\n### ~~CredentialsResponseElementType~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nThe type of the credentials set.\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`AwsMonitoringKeyBased` | `AwsMonitoringRoleBased` | `Certificate` | `PublicCertificate` | `Snmpv3` | `Token` | `Unknown` | `UsernamePassword`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialsscope\"></a>\n### ~~CredentialsScope~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nThe scope of the credentials set.\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`AppEngine` | `Extension` | `ExtensionAuthentication` | `Synthetic`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialsscopesitem\"></a>\n### ~~CredentialsScopesItem~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nThe set of scopes of the credentials set.\n\n Limitations: `CredentialsScope.APP_ENGINE` is only available on the new Dynatrace SaaS platform - it&apos;s not available on managed or non-Grail SaaS environments.\n\n#### Enum keys\n\n<div class=\"padding-left--md\">\n\n`AppEngine` | `Extension` | `ExtensionAuthentication` | `Synthetic`\n\n</div>\n\n\n</div>\n\n<a name=\"credentialstype\"></a>\n### ~~CredentialsType~~\n\n> ⚠️ **Deprecated**\n> Use literal values.\n\n<div class=\"padding-left--md\">\n\nDefines the actual set of fields depending on the value. See one of the following objects:\n\n* `CERTIFICATE` -&gt; CertificateCredentials\n* `PUBLIC_CERTIFICATE` -&gt; PublicCertificateCredentials\n* `USERNAME_PASSWORD` -&gt; UserPasswordCredentials\n* `TOKEN` -&gt; TokenCredentials\n* `SNMPV3` -&gt; SNMPV3Credentials\n* `AWS_MONITORING_K","readmeFilename":"README.md","_rev":"1-9d3125e517b3df0d278e63507089e646"}