Skip to main content
To call the Infisical API, you need to authenticate as a machine identity using one of the authentication methods listed below. The authentication method returns a short-lived access token. Include that token as an Authorization: Bearer <token> header on every Infisical API request.
For a guide on authenticating with Universal Auth and calling the API, check out the Quickstart.

Authentication methods

Each authentication method accepts a different type of credential:

Infisical-issued credentials

These methods accept credentials that Infisical creates and manages directly, such as a client ID and client secret or a long-lived access token. They work from any environment.

Universal Auth

Authenticate with a client ID and client secret.

Token Auth

Authenticate with a long-lived, manually issued access token.

Cloud providers

Cloud providers accept the identity the calling workload already has on that cloud, such as an IAM role, a managed identity, or a service account.

AWS Auth

Authenticate from an EC2 instance, ECS task, Lambda function, or any AWS workload with an IAM role.

Azure Auth

Authenticate from an Azure workload with a managed identity.

GCP Auth

Authenticate from a Compute Engine instance, GKE pod, or Cloud Run service using its GCP service account.

Kubernetes Auth

Authenticate from a Kubernetes pod using its service account token.

OCI Auth

Authenticate from an Oracle Cloud compute instance using its instance principal.

AliCloud Auth

Authenticate from an Alibaba Cloud workload using an assumed RAM role.

External identity

These methods accept a credential from a trusted external system, such as an OIDC identity token, a JWT signed by a trusted issuer, an LDAP bind, a client certificate, or a SPIFFE SVID.

OIDC Auth

Authenticate with an OIDC identity token from a trusted OIDC provider.

JWT Auth

Authenticate with a JWT signed by a trusted issuer.

LDAP Auth

Authenticate against a configured LDAP directory.

TLS certificate Auth

Authenticate with a client certificate signed by a trusted certificate authority.

SPIFFE Auth

Authenticate with a SPIFFE SVID from a workload attested by SPIRE.

FAQ

A few reasons this can happen:
  • The calling identity doesn’t have the org permissions required to manage identities
  • The identity being changed is more privileged than the calling identity
  • The role being assigned is more privileged than any role held by the calling identity
A few reasons this can happen:
  • The client secret or access token has expired
  • The identity doesn’t have the permissions required by the endpoint
  • The client secret or access token is being used from an IP address the identity doesn’t trust