- Support
- Integrations
- Vault
Vault
Oracle Cloud integration · 50 node(s).
00Overview
Create and manage Oracle Cloud vaults, master encryption keys and their versions straight from a flow, then use those keys to encrypt, decrypt, sign and verify data or generate data encryption keys for larger payloads. Store, update, rotate and retrieve secrets, move keys and secrets between compartments, and back up or replicate a vault to another region. Deletions are staged and reversible, so a flow can schedule, cancel or restore keys, secrets and whole vaults as your automation needs change.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Vault
- Decide how the node authenticates with the Authentication dropdown: Connect Oracle Cloud uses an Oracle Cloud account you have already linked to Flomation, while API signing key (advanced) lets you supply the raw signing-key credentials on the node itself.
- For Connect Oracle Cloud, link the account once in Flomation's connections, then choose it in the node's Oracle Cloud connection field — there are no keys to copy by hand.
- For API signing key (advanced), sign in to the Oracle Cloud Console, open the Profile menu (top-right) → My profile → API keys, and choose Add API key to generate a key pair — download the private key when prompted.
- Once the key is added, OCI shows a Configuration file preview: copy its
uservalue into User OCID,tenancyinto Tenancy OCID,fingerprintinto Key Fingerprint andregioninto Region. - Set the Compartment OCID to the compartment that holds (or will hold) your vaults, keys and secrets — list and create actions are scoped to it.
- Store the downloaded private key as a Flomation environment secret (e.g.
vault_secret) and pick it in the node's Private Key (PEM) field; fill Private Key Passphrase only if the key is encrypted.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Decrypt
OCI Vault: Decrypt
oracle/vault/decrypt · Action
Decrypt ciphertext with the master key that produced it, via the vault's crypto endpoint. Pass the base64 ciphertext returned by Encrypt; the recovered plaintext comes back base64-encoded.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… that encrypted the data |
| Ciphertext (base64) | text | Required | The base64 ciphertext returned by Encrypt |
Returns: tool_result, plaintext, plaintext_checksum, key_id, success, error
03Encrypt
OCI Vault: Encrypt
oracle/vault/encrypt · Action
Encrypt data (≤ 4KB) with a master key via the vault's crypto endpoint. The plaintext must be base64-encoded; the ciphertext returns base64-encoded — feed it to Decrypt to recover the data. For larger data, use Generate Data Encryption Key.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to encrypt with |
| Plaintext (base64) | text | Required | The data to encrypt, base64-encoded (≤ 4KB) |
Returns: tool_result, ciphertext, key_id, success, error
04Export
OCI Vault: Export Key
oracle/vault/export_key · Action
Wrap and export a master key's material via the vault's crypto endpoint. The key must have been created exportable. Supply your own RSA wrapping public key (PEM); the material returns encrypted with it, so only the matching private key can unwrap it. RSA_OAEP_AES_SHA256 uses AES key-wrap; RSA_OAEP_SHA256 wraps the material directly.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to export (must be exportable) |
| Wrapping Public Key (PEM) | text | Required | Your 2048/3072/4096-bit RSA public key — full PEM, incl. BEGIN/END lines |
| Wrapping Algorithm | string | Required | RSA_OAEP_AES_SHA256 or RSA_OAEP_SHA256 — choices: RSA-OAEP AES (SHA-256), RSA-OAEP (SHA-256) |
Returns: tool_result, encrypted_key, key_version_id, success, error
05Generate
OCI Vault: Generate Data Encryption Key
oracle/vault/generate_data_encryption_key · Action
Generate a data encryption key (DEK) under a master key, via the vault's crypto endpoint — for envelope encryption of larger data. The DEK returns wrapped (encrypted) with the master key as the ciphertext; the plaintext DEK is included only when Include Plaintext Key is on.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… the master key to wrap the DEK with |
| Algorithm | string | AES (default), RSA or ECDSA — choices: AES (symmetric), RSA, ECDSA | |
| Length (bytes) | string | Optional — AES 16/24/32 (default 32); RSA 256/384/512 (default 256) | |
| Include Plaintext Key | boolean | Also return the DEK unencrypted (default true) |
Returns: tool_result, ciphertext, plaintext, plaintext_checksum, success, error
06Key
OCI Vault: Back Up Key
oracle/vault/key_backup · Action
Back up an Oracle Cloud master encryption key (resolved via the vault's management endpoint) to an Object Storage bucket or a pre-authenticated URI.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to back up |
| Bucket Namespace | string | Object Storage namespace holding the destination bucket | |
| Bucket Name | string | Destination bucket for the backup | |
| Object Name | string | Optional object name for the backup (OCI names it if blank) | |
| Backup URI | string | Pre-authenticated request URI (alternative to a bucket) |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Cancel Key Deletion
oracle/vault/key_cancel_deletion · Action
Cancel a scheduled deletion of an Oracle Cloud master encryption key (resolved via the vault's management endpoint), restoring it from pending-deletion.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… that holds the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to cancel deletion for |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Move Key to Compartment
oracle/vault/key_change_compartment · Action
Move an Oracle Cloud master encryption key (resolved via its vault's management endpoint) into a different compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… holding the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to move |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… to move the key into |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Vault: Create Key
oracle/vault/key_create · Action
Create a master encryption key in an Oracle Cloud vault — used to encrypt/decrypt data and protect secrets. Pick the algorithm (AES/RSA/ECDSA); for ECDSA choose the curve. Defaults to a SOFTWARE-protected key; poll Get Key until ENABLED.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Display Name | string | Required | A friendly name for the key |
| Algorithm | string | AES (default), RSA or ECDSA — choices: AES (symmetric), RSA, ECDSA | |
| Curve (ECDSA only) | string | The elliptic curve for ECDSA keys — default NIST_P256 — choices: NIST P-256, NIST P-384, NIST P-521 | |
| Length (bytes) | string | Optional — AES 16/24/32 (default 32); RSA 256/384/512 (default 256); ECDSA is set by the curve | |
| Protection Mode | string | SOFTWARE (default) or HSM — choices: Software, HSM | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Disable Key
oracle/vault/key_disable · Action
Disable a master encryption key in an Oracle Cloud vault so it can no longer encrypt, decrypt, or protect secrets until re-enabled. Resolved via the vault's management endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to disable |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Enable Key
oracle/vault/key_enable · Action
Re-enable a disabled master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint), returning it to the ENABLED state so it can be used again.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to enable |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Get Key
oracle/vault/key_get · Action
Fetch a single master encryption key from an Oracle Cloud vault by its OCID (resolved via the vault's management endpoint).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to fetch |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: List Keys
oracle/vault/key_list · Action
List the master encryption keys in an Oracle Cloud vault (resolved via the vault's management endpoint), in a compartment. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… to list keys from |
Returns: tool_result, keys, count, truncated, success, error
OCI Vault: Restore Key
oracle/vault/key_restore · Action
Restore a master encryption key into an Oracle Cloud vault from an Object Storage backup (a bucket or a pre-authenticated URI). Creates a new key.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… of the vault to restore the key into |
| Bucket Namespace | string | Object Storage namespace holding the backup | |
| Bucket Name | string | Bucket holding the key backup | |
| Object Name | string | Object name of the key backup within the bucket | |
| Backup URI | string | Pre-authenticated request URI (alternative to a bucket) |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Schedule Key Deletion
oracle/vault/key_schedule_deletion · Action
Schedule a master encryption key in an Oracle Cloud vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first. Resolved via the vault's management endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to schedule for deletion |
| Time of Deletion (RFC3339) | string | e.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Update Key
oracle/vault/key_update · Action
Update a master encryption key in an Oracle Cloud vault — change its display name and/or replace its freeform tags (resolved via the vault's management endpoint).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… the key lives in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to update |
| Display Name | string | A new friendly name for the key (optional) | |
| Freeform Tags (JSON) | string | {"env":"prod"} — replaces existing tags (optional) |
Returns: tool_result, key, id, lifecycle_state, success, error
OCI Vault: Cancel Key Version Deletion
oracle/vault/key_version_cancel_deletion · Action
Cancel a pending deletion of a key version in an Oracle Cloud vault (resolved via the vault's management endpoint), returning it to an enabled state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… holding the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… the version belongs to |
| Key Version OCID | string | Required | ocid1.keyversion.oc1..aaaa… to cancel deletion for |
Returns: tool_result, key_version, id, lifecycle_state, success, error
OCI Vault: Create Key Version
oracle/vault/key_version_create · Action
Create a new key version for a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint), rotating the key's active material.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… holding the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to create a new version for |
Returns: tool_result, key_version, id, lifecycle_state, success, error
OCI Vault: Get Key Version
oracle/vault/key_version_get · Action
Fetch a single key version of a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… holding the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… whose version to fetch |
| Key Version OCID | string | Required | ocid1.keyversion.oc1..aaaa… to fetch |
Returns: tool_result, key_version, id, lifecycle_state, success, error
OCI Vault: List Key Versions
oracle/vault/key_version_list · Action
List the versions of a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint). Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… holding the key |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to list versions of |
Returns: tool_result, key_versions, count, truncated, success, error
OCI Vault: Schedule Key Version Deletion
oracle/vault/key_version_schedule_deletion · Action
Schedule a specific version of an Oracle Cloud master key for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… |
| Key Version OCID | string | Required | ocid1.keyversion.oc1..aaaa… |
| Time of Deletion (RFC3339) | string | e.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days |
Returns: tool_result, key_version, id, lifecycle_state, success, error
07Secret
OCI Vault: Get Secret Bundle
oracle/vault/secret_bundle_get · Action
Retrieve the contents of a secret (its base64-encoded value plus version metadata) from an Oracle Cloud vault. Defaults to the current version; pass a version number or stage (CURRENT/PENDING/LATEST/PREVIOUS/DEPRECATED) to fetch a specific one.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the secret picker) | |
| Vault OCID | string | ocid1.vault.oc1..aaaa… (scopes the secret picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… to retrieve |
| Version Number | string | A specific version number (optional; defaults to current) | |
| Stage | string | CURRENT (default), PENDING, LATEST, PREVIOUS or DEPRECATED — choices: Current, Pending, Latest, Previous, Deprecated |
Returns: tool_result, content, version_number, version_name, secret_id, success, error
OCI Vault: Get Secret Bundle by Name
oracle/vault/secret_bundle_get_by_name · Action
Retrieve the contents of a secret (its base64-encoded value plus version metadata) by the secret's name within an Oracle Cloud vault. Defaults to the current version; pass a version number or stage (CURRENT/PENDING/LATEST/PREVIOUS/DEPRECATED) to fetch a specific one.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the secret picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… that contains the secret |
| Secret Name | string | Required | The secret's name (unique within the vault, case-sensitive) |
| Version Number | string | A specific version number (optional; defaults to current) | |
| Stage | string | CURRENT (default), PENDING, LATEST, PREVIOUS or DEPRECATED — choices: Current, Pending, Latest, Previous, Deprecated |
Returns: tool_result, content, version_number, version_name, secret_id, success, error
OCI Vault: List Secret Bundle Versions
oracle/vault/secret_bundle_versions_list · Action
List all bundle versions of a secret in an Oracle Cloud vault — each version's number, name, rotation stages and creation time — from the secrets-retrieval endpoint. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the secret picker) | |
| Vault OCID | string | ocid1.vault.oc1..aaaa… (scopes the secret picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… whose versions to list |
Returns: tool_result, versions, count, truncated, success, error
OCI Vault: Cancel Secret Deletion
oracle/vault/secret_cancel_deletion · Action
Cancel a pending secret deletion in an Oracle Cloud vault, returning the secret to ACTIVE before its scheduled deletion time elapses.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… whose pending deletion to cancel |
Returns: tool_result, secret, id, lifecycle_state, success, error
OCI Vault: Move Secret to Compartment
oracle/vault/secret_change_compartment · Action
Move a secret from its current compartment into another compartment within the same Oracle Cloud tenancy.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… to move |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… to move the secret into |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Vault: Create Secret
oracle/vault/secret_create · Action
Store a new secret in an Oracle Cloud vault, encrypted under a master key. The content must be base64-encoded. Poll Get Secret until ACTIVE, then retrieve it with Get Secret Bundle.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… to store the secret in |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to encrypt the secret with |
| Secret Name | string | Required | Unique name within the vault (letters, numbers, hyphens) |
| Secret Content (base64) | text | Required | The secret value, base64-encoded |
| Description | string | What this secret is for (optional) | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, secret, id, lifecycle_state, success, error
OCI Vault: Get Secret
oracle/vault/secret_get · Action
Fetch a secret's metadata by OCID (name, vault, key, current version, lifecycle state). Does not return the secret value — use Get Secret Bundle for that.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… to fetch |
Returns: tool_result, secret, id, lifecycle_state, success, error
OCI Vault: List Secrets
oracle/vault/secret_list · Action
List the secrets in an Oracle Cloud compartment, optionally filtered to a single vault and/or an exact secret name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Vault OCID | string | ocid1.vault.oc1..aaaa… to filter to (optional) | |
| Secret Name | string | Filter to an exact secret name (optional) |
Returns: tool_result, secrets, count, truncated, success, error
OCI Vault: Schedule Secret Deletion
oracle/vault/secret_schedule_deletion · Action
Schedule the deletion of a secret in an Oracle Cloud vault — OCI removes it at the chosen time (or the earliest permissible time if none is given), and it stays cancellable until then.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the secret picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… to schedule for deletion |
| Time of Deletion (RFC3339) | string | e.g. 2026-08-01T00:00:00Z — leave blank for the earliest permissible time (optional) |
Returns: tool_result, id, success, error
OCI Vault: Update Secret
oracle/vault/secret_update · Action
Update an Oracle Cloud secret's description or tags, and optionally set new base64-encoded content — which creates a new secret version.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… of the secret to update |
| Secret Content (base64) | text | New secret value, base64-encoded — sets a new version (optional) | |
| Description | string | What this secret is for (optional) | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, secret, id, lifecycle_state, success, error
OCI Vault: Cancel Secret Version Deletion
oracle/vault/secret_version_cancel_deletion · Action
Cancel a pending deletion of a single secret version in an Oracle Cloud vault, returning it to the secret before its scheduled deletion time elapses.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… the version belongs to |
| Version Number | string | Required | The secret version number whose pending deletion to cancel |
Returns: tool_result, secret_version, success, error
OCI Vault: Get Secret Version
oracle/vault/secret_version_get · Action
Fetch the metadata for one version of a secret — its stages, content type and creation time. This is version metadata, not the secret value; retrieve the content with Get Secret Bundle.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… whose version to fetch |
| Version Number | string | Required | The version number, a whole number (e.g. 1) |
Returns: tool_result, secret_version, success, error
OCI Vault: List Secret Versions
oracle/vault/secret_version_list · Action
List the versions of a single Oracle Cloud vault secret, newest first, showing each version's number, rotation stages and creation time. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… to list versions of |
Returns: tool_result, versions, count, truncated, success, error
OCI Vault: Schedule Secret Version Deletion
oracle/vault/secret_version_schedule_deletion · Action
Schedule a specific version of a secret in an Oracle Cloud vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Secret OCID | string | Required | ocid1.vaultsecret.oc1..aaaa… whose version to schedule for deletion |
| Version Number | string | Required | The version number, a whole number (e.g. 1) |
| Time of Deletion (RFC3339) | string | e.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days |
Returns: tool_result, secret_version, id, version_number, success, error
08Sign
OCI Vault: Sign
oracle/vault/sign · Action
Sign a message (or its digest) with a master key via the vault's crypto endpoint. The message must be base64-encoded (≤ 4KB); the signature returns base64-encoded — verify it with Verify. For large data, hash it and sign the DIGEST.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… to sign with (RSA or ECDSA) |
| Message (base64) | text | Required | The message or digest to sign, base64-encoded (≤ 4KB) |
| Signing Algorithm | string | Required | Match the key type (RSA or ECDSA) and the digest's hash — choices: SHA-224 RSA PKCS PSS, SHA-256 RSA PKCS PSS, SHA-384 RSA PKCS PSS, SHA-512 RSA PKCS PSS, SHA-224 RSA PKCS1 v1.5, SHA-256 RSA PKCS1 v1.5, SHA-384 RSA PKCS1 v1.5, SHA-512 RSA PKCS1 v1.5, ECDSA SHA-256, ECDSA SHA-384, ECDSA SHA-512 |
| Message Type | string | RAW (default) or DIGEST — choices: Raw message, Message digest |
Returns: tool_result, signature, key_version_id, success, error
09Vault
OCI Vault: Back Up Vault
oracle/vault/vault_backup · Action
Back up an Oracle Cloud Vault (optionally including its keys) to an Object Storage bucket or a pre-authenticated URI.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Bucket Namespace | string | Object Storage namespace holding the destination bucket | |
| Bucket Name | string | Destination bucket for the backup | |
| Object Name | string | Optional object name for the backup (OCI names it if blank) | |
| Backup URI | string | Pre-authenticated request URI (alternative to a bucket) | |
| Include Keys | boolean | Include the vault's keys in the backup (default true) |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Cancel Vault Deletion
oracle/vault/vault_cancel_deletion · Action
Cancel a scheduled deletion of an Oracle Cloud Vault, restoring it to its active state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Move Vault to Compartment
oracle/vault/vault_change_compartment · Action
Move an Oracle Cloud Vault into a different compartment by OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… — the compartment to move the vault to |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Vault: Create Vault
oracle/vault/vault_create · Action
Create an Oracle Cloud Vault — the container for master encryption keys and secrets. A DEFAULT vault is shared, VIRTUAL_PRIVATE is dedicated. Returns the OCID immediately in a CREATING state; poll Get Vault until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name | string | Required | A friendly name for the vault |
| Vault Type | string | DEFAULT (shared) or VIRTUAL_PRIVATE (dedicated) — choices: Default (shared), Virtual Private (dedicated) | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Create Vault Replica
oracle/vault/vault_create_replica · Action
Replicate an Oracle Cloud Vault into another region in the same realm — an asynchronous operation.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Replica Region | string | Required | e.g. uk-cardiff-1 |
Returns: tool_result, id, replica_region, success, error
OCI Vault: Delete Vault Replica
oracle/vault/vault_delete_replica · Action
Remove a cross-region replica of an Oracle Cloud Vault — asynchronous; OCI tears the replica down in the background.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Replica Region | string | Required | The region whose replica to remove, e.g. uk-cardiff-1 |
Returns: tool_result, id, replica_region, success, error
OCI Vault: Get Vault
oracle/vault/vault_get · Action
Fetch a single Oracle Cloud Vault by OCID — its type, lifecycle state, and its management and crypto endpoints.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Get Vault Usage
oracle/vault/vault_get_usage · Action
Report how many keys and key versions a Vault holds — HSM and software counts, across all compartments (excluding deleted).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
Returns: tool_result, key_count, key_version_count, software_key_count, software_key_version_count, success, error
OCI Vault: List Vaults
oracle/vault/vault_list · Action
List the Oracle Cloud Vaults in a compartment. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
Returns: tool_result, vaults, count, truncated, success, error
OCI Vault: List Vault Replicas
oracle/vault/vault_list_replicas · Action
List the cross-region replicas of an Oracle Cloud Vault. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
Returns: tool_result, replicas, count, truncated, success, error
OCI Vault: Restore Vault
oracle/vault/vault_restore · Action
Restore an Oracle Cloud Vault from an Object Storage backup into a new vault — supply either the bucket location (namespace, bucket, object) or a pre-authenticated request URI. Returns the OCID immediately; poll Get Vault until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (the compartment to restore the vault into) |
| Bucket Namespace | string | Object Storage namespace holding the backup (with bucket + object) | |
| Bucket Name | string | Bucket that holds the backup object (with namespace + object) | |
| Object Name | string | Name of the backup object in the bucket (with namespace + bucket) | |
| Backup PAR URI | string | Pre-authenticated request URI to the backup (alternative to the bucket fields) |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Schedule Vault Deletion
oracle/vault/vault_schedule_deletion · Action
Schedule an Oracle Cloud Vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Time of Deletion (RFC3339) | string | e.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days |
Returns: tool_result, vault, id, lifecycle_state, success, error
OCI Vault: Update Vault
oracle/vault/vault_update · Action
Update an Oracle Cloud Vault's display name and/or its free-form tags, addressed by OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… |
| Display Name | string | A new, human-friendly name for the vault (optional) | |
| Free-form Tags | string | Replaces all free-form tags, e.g. {"env":"prod"} (optional) |
Returns: tool_result, vault, id, lifecycle_state, success, error
10Verify
OCI Vault: Verify Signature
oracle/vault/verify · Action
Verify a cryptographic signature against a message via the vault's crypto endpoint. Provide the base64 message (or its digest), the base64 signature, and the same key, signing algorithm and message type that produced it. Returns is_valid true or false.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the vault/key pickers) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… (its crypto endpoint is used) |
| Key OCID | string | Required | ocid1.key.oc1..aaaa… that signed the message |
| Message (base64) | text | Required | The base64-encoded message, or its digest (≤ 4KB) |
| Signature (base64) | text | Required | The base64-encoded signature to verify |
| Signing Algorithm | string | Required | The algorithm that produced the signature — choices: SHA-224 RSA PKCS#1 v1.5, SHA-256 RSA PKCS#1 v1.5, SHA-384 RSA PKCS#1 v1.5, SHA-512 RSA PKCS#1 v1.5, SHA-224 RSA PSS, SHA-256 RSA PSS, SHA-384 RSA PSS, SHA-512 RSA PSS, ECDSA SHA-256, ECDSA SHA-384, ECDSA SHA-512 |
| Message Type | string | RAW (default) or DIGEST — choices: Raw message, Message digest |
Returns: tool_result, is_valid, success, error
11Wrapping
OCI Vault: Get Wrapping Key
oracle/vault/wrapping_key_get · Action
Fetch an Oracle Cloud vault's RSA wrapping key (resolved via the vault's management endpoint) — use its public key to wrap external key material before importing it with Import Key.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | ocid1.compartment.oc1..aaaa… (scopes the picker) | |
| Vault OCID | string | Required | ocid1.vault.oc1..aaaa… to fetch the wrapping key for |
Returns: tool_result, public_key, id, lifecycle_state, success, error
12Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Key and crypto operations run against each vault's own management and crypto endpoints, whose DNS can lag a few minutes behind the vault first reporting ACTIVE, so calls against a freshly created vault may fail briefly with a "still provisioning" message until the endpoint resolves.
- Get Secret returns only a secret's metadata (name, vault, key, current version and lifecycle state); the value itself is retrieved separately with Get Secret Bundle or Get Secret Bundle by Name, which return it base64-encoded.
- Vaults, keys and key versions cannot be deleted immediately — deletion is scheduled 7 to 30 days out (30 days by default) and stays cancellable until that time elapses, while secret deletions are likewise staged and remain reversible until their scheduled time.
- Create and restore actions for vaults, keys and secrets return an OCID in a provisioning state, so poll Get Vault, Get Key or Get Secret until the resource reaches ACTIVE or ENABLED before using it.
- Encrypt, Sign and Verify accept at most 4 KB of base64-encoded input; for larger payloads use Generate Data Encryption Key for envelope encryption, or hash the data and sign the digest.
- Export Key succeeds only on a key that was created as exportable, and that capability cannot be added to an existing key afterwards.