Create a generic Vault Account.

Adds a new username / password account, SSH account or X.509 account. Windows local and domain accounts cannot be added via this API.

The request body must either be a VaultUsernamePasswordAccount, VaultTokenAccount, VaultSSHAccount, VaultX509ImportedCAAccount, VaultX509GeneratedCAAccount, or VaultX509ClientAccount resource.

After an account is added via the API, the Vault Account Activity Report shows an "Account Created" event for that account. The "User" column shows the name of the API Account that created the account.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

New account properties.

string
enum
required
Allowed:
string
required
length between 1 and 255

The name of the Account.

string
required
length between 1 and 255

The username that will be injected and/or checked out.

string
required
length between 1 and 255

The password that will be injected and/or checked out.

string
length ≤ 4096

The Account's description.

int32
1 to 2147483647
Defaults to 1

The unique identifier the Vault Account Group. The account_group_id defaults to 1, which is the default Account Group.

string | null

The code name of the Account Policy associated with the account. When the value is null, the account policy is inherited from the account group. If there is no account group, it is inherited from the global default.

Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.