Agent skill

Vault API

by Kilo-Org in Kilo-Org/kilo-marketplace

A skill your agent uses when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations.

MITAuto-check passedBackend & APIs

Install Vault API

skills CLI
$ npx skills add Kilo-Org/kilo-marketplace --skill vault-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Kilo-Org/kilo-marketplace vault-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vault-api .claude/skills/vault-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vault-api
GitHub stars
190
Token cost
~1.8k tokens
SKILL.md length
519 words
Files
2
Skills in repo
85
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations.

  • Working with HashiCorp Vault REST API — health checks
  • SKILL.md covers Overview, API Endpoints, Auth Methods Summary and Health Check Examples, plus 1 more section
  • Calls curl, jq and kubectl; reaches vault.vault and vault.kubexa.tech; needs VAULT_TOKEN
  • Policy management

What it does

Vault API is an agent skill from Kilo-Org/kilo-marketplace. Use when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations. Covers endpoints, auth methods, curl examples.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Backend & APIs, covering REST APIs. It works with HashiCorp Vault. The repository describes itself as: Kilo Marketplace - A curated collection of Skills, MCP Servers, and Modes for enhancing AI agent capabilities across the Kilo ecosystem—including Kilo Code (VS Code extension)… The licence is MIT.

When your agent uses it

  • Working with HashiCorp Vault REST API — health checks
  • Policy management
  • Token operations

Example prompts

  • “/vault-api”

Requirements

  • A credential in VAULT_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit ff51758. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • vault.vault
    • vault.kubexa.tech

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VAULT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vault API loads about 1.8k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 519 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Kilo-Org/kilo-marketplace at commit ff51758, republished under its MIT licence (© Kilo-Org). 519 words, ~1,820 tokens.

Download SKILL.mdSave it as .claude/skills/vault-api/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
vault-api
description
Use when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations. Covers endpoints, auth methods, curl examples.
metadata.category
development

Vault API

Overview

Vault exposes a RESTful JSON API on port 8200. All requests include X-Vault-Token header for authenticated endpoints. Unauthenticated endpoints (health, init) need no token.

Base URL: http://vault.vault:8200 (in-cluster) or https://vault.kubexa.tech (external via Gateway).

API Endpoints

System
MethodEndpointDescriptionAuth
GET/v1/sys/healthCluster health (see status codes below)No
GET/v1/sys/seal-statusSeal statusNo
PUT/v1/sys/initInitialize clusterNo
PUT/v1/sys/unsealUnseal (submit key share)No
GET/v1/sys/leaderCurrent leader infoNo

Health status codes:

CodeMeaning
200Active, unsealed
429Standby, unsealed
472Disaster Recovery secondary (enterprise)
473Performance standby (enterprise)
501Not initialized
503Sealed
Auth (Kubernetes)
MethodEndpointDescription
POST/v1/auth/kubernetes/loginLogin with service account JWT
bash
# Login with K8s SA token
SA_JWT=$(kubectl create token my-sa -n my-ns)
curl -s http://vault.vault:8200/v1/auth/kubernetes/login \
  -d "{\"role\":\"my-role\",\"jwt\":\"$SA_JWT\"}"
# Returns: {"auth":{"client_token":"hvs...","policies":["my-policy"]}}
KV Secrets (v2)
MethodEndpointDescription
GET/v1/{mount}/data/{path}Read secret
PUT/v1/{mount}/data/{path}Create/update secret
DELETE/v1/{mount}/data/{path}Delete latest version
GET/v1/{mount}/metadata/{path}Read metadata (versions, timestamps)
POST/v1/{mount}/delete/{path}Delete all versions
POST/v1/{mount}/undelete/{path}Undelete
bash
# Write a secret
curl -s http://vault.vault:8200/v1/secret/data/myapp \
  -H "X-Vault-Token: $VAULT_TOKEN" \
  -d '{"data":{"password":"s3cret!"}}'

# Read a secret
curl -s http://vault.vault:8200/v1/secret/data/myapp \
  -H "X-Vault-Token: $VAULT_TOKEN"
# Returns: {"data":{"data":{"password":"s3cret!"},"metadata":{...}}}

# List secrets at a path
curl -s http://vault.vault:8200/v1/secret/metadata/myapp \
  -H "X-Vault-Token: $VAULT_TOKEN" \
  | jq '.data.keys'
KV Secrets (v1)
MethodEndpointDescription
GET/v1/{mount}/{path}Read secret
PUT/v1/{mount}/{path}Create/update secret
DELETE/v1/{mount}/{path}Delete secret
Policies
MethodEndpointDescription
GET/v1/sys/policies/aclList ACL policies
GET/v1/sys/policies/acl/{name}Read policy
PUT/v1/sys/policies/acl/{name}Create/update policy
DELETE/v1/sys/policies/acl/{name}Delete policy
bash
# Create read-only policy for myapp
curl -s http://vault.vault:8200/v1/sys/policies/acl/myapp \
  -X PUT \
  -H "X-Vault-Token: $VAULT_TOKEN" \
  -d '{"policy":"path \"secret/data/myapp/*\" {capabilities=[\"read\",\"list\"]}"}'
Token
MethodEndpointDescription
POST/v1/auth/token/createCreate token
POST/v1/auth/token/create-orphanCreate orphan token
GET/v1/auth/token/lookup-selfValidate/lookup own token
POST/v1/auth/token/renew-selfRenew own token
POST/v1/auth/token/revoke-selfRevoke own token
Auth Methods
MethodEndpointDescription
GET/v1/sys/authList enabled auth methods
POST/v1/sys/auth/{type}Enable auth method
DELETE/v1/sys/auth/{path}Disable auth method
Secrets Engines
MethodEndpointDescription
GET/v1/sys/mountsList enabled secret engines
POST/v1/sys/mounts/{path}Enable secret engine (type: kv-v2, kv, transit, etc.)
DELETE/v1/sys/mounts/{path}Disable/delete secret engine
Raft
MethodEndpointDescription
POST/v1/sys/storage/raft/joinJoin Raft cluster
GET/v1/sys/storage/raft/configurationList Raft peers
POST/v1/sys/storage/raft/snapshotTake Raft snapshot
bash
# Join Raft cluster
curl -s http://127.0.0.1:8200/v1/sys/storage/raft/join \
  -X POST \
  -d '{"leader_api_addr":"http://vault-0.vault-internal:8200"}'

# Take snapshot
curl -s http://vault.vault:8200/v1/sys/storage/raft/snapshot \
  -H "X-Vault-Token: $VAULT_TOKEN" \
  -o vault-snapshot.snap

Auth Methods Summary

MethodEndpoint MountUse Case
Kubernetes/v1/auth/kubernetes/loginIn-cluster pods via SA JWT
Token/v1/auth/token/createRoot token, periodic tokens
AppRole/v1/auth/approle/loginMachine-to-machine (w/ secretId)
Userpass/v1/auth/userpass/loginHuman users
LDAP/v1/auth/ldap/loginEnterprise directory integration
JWT/OIDC/v1/auth/jwt/loginExternal OIDC providers
Cert/v1/auth/cert/loginmTLS client certificates
Show full SKILL.md (196 more words)Show less

Health Check Examples

bash
# Quick health
curl -s http://vault.vault:8200/v1/sys/health | jq .initialized

# Detailed status
curl -s http://vault.vault:8200/v1/sys/seal-status | jq '.sealed, .t, .n, .progress'

Common Mistakes

  • KV v2 path includes data/ prefix. For KV v2 engine mounted at secret, the read path is /v1/secret/data/myapp, not /v1/secret/myapp. The latter returns a 404.
  • Health endpoint returns non-200 for sealed/standby. A 503 (sealed) is NOT an error — it's expected after restart. Check initialized and sealed fields in the response body, not the HTTP status alone.
  • Token in URL is stripped by proxies. Use X-Vault-Token header, not ?token= query param. Proxies and load balancers may log or strip query params.
  • Kubernetes auth needs SA token with right audience. The vault audience must be configured in the SA or the default token may not be accepted. Use kubectl create token with --audience=vault for explicit audience.
  • list capabilities for metadata listing. Reading /v1/secret/metadata/ (to list keys) requires list capability at that path, not read. Without it, the response is empty.
  • Raft join after unseal. A sealed node cannot join the Raft cluster. Always unseal before raft join. The joining node will sync data from the leader.
  • Snapshot restore requires same cluster size. Raft snapshots can only be restored to a cluster with the same number of peers. Adding/removing nodes after restore may fail.

© Kilo-Org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/vault-api of Kilo-Org/kilo-marketplace.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit ff51758

Compare with similar skills

Vault API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vault API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vault API this skillKilo-Org/kilo-marketplace190—~1.8kAutomated safety check: PassMIT
Backend Dev Guidelineslangfuse/langfuse36k—~1.9kAutomated safety check: PassCustom licence
DormiceBitMiracle-AI/Dormice1.4k—~2.7kAutomated safety check: NotesApache-2.0
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Ship Coolifykovrichard/catalyst470—~1.9kAutomated safety check: NotesNone
Frappe Ops Website DeployImpertio-Studio/Frappe_Claude_Skill_Package187—~2.5kAutomated safety check: PassMIT

Similar skills

  • Backend Dev Guidelines

    langfuse/langfuse

    Build or review Langfuse backend code. An agent skill from langfuse/langfuse.

    36k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Dormice

    BitMiracle-AI/Dormice

    Operate Dormice self-hosted agent sandboxes — acquire a sandbox, run commands, move files, tune lifecycle policy — through the official E2B SDKs, the native HTTP API and SDK, or the dor CLI.

    1.4k GitHub stars~2.7k tokensUpdated 6 days ago
    Backend & APIsAuto-check: notes
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Ship Coolify

    kovrichard/catalyst

    Verify a Coolify deploy end-to-end after a push — wait for GitHub CI, then the Coolify deployment, confirm the commit is live, and run a visual check.

    470 GitHub stars~1.9k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Frappe Ops Website Deploy

    Impertio-Studio/Frappe_Claude_Skill_Package

    Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.

    187 GitHub stars~2.5k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed
  • Finding Triage

    HacktronAI/skills

    Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…

    115 GitHub stars~2.9k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes

More from Kilo-Org/kilo-marketplace

All 85 skills in this repo
  • AzureML Project Scaffolding

    Kilo-Org/kilo-marketplace

    Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.

    190 GitHub stars~3.1k tokensUpdated 9 days ago
    Auto-check: notes
  • Jupyter Notebook Builder

    Kilo-Org/kilo-marketplace

    Creates, inspects, edits and runs Jupyter notebooks, scaffolding experiment or tutorial notebooks from templates and preferring a Jupyter MCP server over raw JSON edits.

    190 GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Tableau Dashboard Creator

    Kilo-Org/kilo-marketplace

    Takes a plain-language dashboard request through brand setup, data exploration, planning, an interactive HTML mock and a Tableau implementation spec.

    190 GitHub stars~3.8k tokensUpdated 9 days ago
    Auto-check: notes
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 9 days ago
    Auto-check passed
  • Nifi Flow Layout

    Kilo-Org/kilo-marketplace

    A skill your agent uses when arranging Apache NiFi processors, process groups, ports, comments, numbering, crossing connections, dense fan-in/fan-out, or reusable readable canvas layouts.

    190 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Splunk Ingest Processor Setup

    Kilo-Org/kilo-marketplace

    Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and…

    190 GitHub stars~1.2k tokensUpdated 9 days ago
    Auto-check passed

Works with

Questions about Vault API

What does Vault API do?

A skill your agent uses when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations. Vault API is an agent skill from Kilo-Org/kilo-marketplace. Use when working with HashiCorp Vault REST API — health checks, init/unseal, auth login, KV read/write, policy management, token operations.

When should I use Vault API?

Vault API fits situations like: working with HashiCorp Vault REST API — health checks; policy management; token operations.

How do I install Vault API in Claude Code?

Run `npx skills add Kilo-Org/kilo-marketplace --skill vault-api -a claude-code`. Or copy the skill folder (skills/vault-api in Kilo-Org/kilo-marketplace) into .claude/skills/vault-api in your project. Claude Code loads it when a task matches its description.

How do I install Vault API in Codex?

Run `npx skills add Kilo-Org/kilo-marketplace --skill vault-api -a codex`. Or copy the skill folder (skills/vault-api in Kilo-Org/kilo-marketplace) into .agents/skills/vault-api in your project. Codex loads it when a task matches its description.

Can I use Vault API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kilo-Org/kilo-marketplace --skill vault-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vault-api, .gemini/skills/vault-api, .github/skills/vault-api and .opencode/skills/vault-api in your project.

What does Vault API need to run?

Going by SKILL.md and its folder, Vault API needs the command-line tools its instructions call (curl, jq and kubectl) and credentials named VAULT_TOKEN. Our summary lists: A credential in VAULT_TOKEN.

Does Vault API access the network?

SKILL.md names 2 domains. In commands or code: vault.vault and vault.kubexa.tech; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Vault API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vault API use?

Vault API is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vault API use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vault API?

Skills that share tags, products or a category with Vault API: Backend Dev Guidelines (langfuse/langfuse, 36k stars), Dormice (BitMiracle-AI/Dormice, 1.4k stars), Mintlify API (macro-inc/macro, 4.6k stars) and Ship Coolify (kovrichard/catalyst, 470 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vault API?

Kilo-Org (a GitHub organization) maintains it in Kilo-Org/kilo-marketplace, which has 190 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on September 28, 2026.

Source: Kilo-Org/kilo-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.