Authorization: Bearer <token> header on every Infisical API request.
For a guide on authenticating with Universal Auth and calling the API, check out the Quickstart.
Authentication methods
Each authentication method accepts a different type of credential:Infisical-issued credentials
These methods accept credentials that Infisical creates and manages directly, such as a client ID and client secret or a long-lived access token. They work from any environment.Universal Auth
Authenticate with a client ID and client secret.
Token Auth
Authenticate with a long-lived, manually issued access token.
Cloud providers
Cloud providers accept the identity the calling workload already has on that cloud, such as an IAM role, a managed identity, or a service account.AWS Auth
Authenticate from an EC2 instance, ECS task, Lambda function, or any AWS workload with an IAM role.
Azure Auth
Authenticate from an Azure workload with a managed identity.
GCP Auth
Authenticate from a Compute Engine instance, GKE pod, or Cloud Run service using its GCP service account.
Kubernetes Auth
Authenticate from a Kubernetes pod using its service account token.
OCI Auth
Authenticate from an Oracle Cloud compute instance using its instance principal.
AliCloud Auth
Authenticate from an Alibaba Cloud workload using an assumed RAM role.
External identity
These methods accept a credential from a trusted external system, such as an OIDC identity token, a JWT signed by a trusted issuer, an LDAP bind, a client certificate, or a SPIFFE SVID.OIDC Auth
Authenticate with an OIDC identity token from a trusted OIDC provider.
JWT Auth
Authenticate with a JWT signed by a trusted issuer.
LDAP Auth
Authenticate against a configured LDAP directory.
TLS certificate Auth
Authenticate with a client certificate signed by a trusted certificate authority.
SPIFFE Auth
Authenticate with a SPIFFE SVID from a workload attested by SPIRE.
FAQ
Why can I not create, read, update, or delete an identity?
Why can I not create, read, update, or delete an identity?
A few reasons this can happen:
- The calling identity doesn’t have the org permissions required to manage identities
- The identity being changed is more privileged than the calling identity
- The role being assigned is more privileged than any role held by the calling identity
Why is the Infisical API rejecting my identity credentials?
Why is the Infisical API rejecting my identity credentials?
A few reasons this can happen:
- The client secret or access token has expired
- The identity doesn’t have the permissions required by the endpoint
- The client secret or access token is being used from an IP address the identity doesn’t trust