1. Support
  2. Integrations
  3. Vault
Oracle Cloud 50 nodes

Vault

Oracle Cloud integration · 50 node(s).

00Overview

Create and manage Oracle Cloud vaults, master encryption keys and their versions straight from a flow, then use those keys to encrypt, decrypt, sign and verify data or generate data encryption keys for larger payloads. Store, update, rotate and retrieve secrets, move keys and secrets between compartments, and back up or replicate a vault to another region. Deletions are staged and reversible, so a flow can schedule, cancel or restore keys, secrets and whole vaults as your automation needs change.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting Vault

  1. Decide how the node authenticates with the Authentication dropdown: Connect Oracle Cloud uses an Oracle Cloud account you have already linked to Flomation, while API signing key (advanced) lets you supply the raw signing-key credentials on the node itself.
  2. For Connect Oracle Cloud, link the account once in Flomation's connections, then choose it in the node's Oracle Cloud connection field — there are no keys to copy by hand.
  3. For API signing key (advanced), sign in to the Oracle Cloud Console, open the Profile menu (top-right) → My profile → API keys, and choose Add API key to generate a key pair — download the private key when prompted.
  4. Once the key is added, OCI shows a Configuration file preview: copy its user value into User OCID, tenancy into Tenancy OCID, fingerprint into Key Fingerprint and region into Region.
  5. Set the Compartment OCID to the compartment that holds (or will hold) your vaults, keys and secrets — list and create actions are scoped to it.
  6. Store the downloaded private key as a Flomation environment secret (e.g. vault_secret) and pick it in the node's Private Key (PEM) field; fill Private Key Passphrase only if the key is encrypted.
FieldTypeDetails
AuthenticationstringConnect Oracle Cloud, API signing key (advanced)
Oracle Cloud connectioncredentialPick a connected Oracle Cloud account
Regionstringe.g. uk-london-1
Private Key (PEM)secretThe API signing private key — full PEM, incl. BEGIN/END lines
Private Key PassphrasesecretOnly if the key is encrypted (optional)
Tenancy OCIDstringocid1.tenancy.oc1..aaaa…
User OCIDstringocid1.user.oc1..aaaa…
Key Fingerprintstringaa:bb:cc:… fingerprint of the uploaded API key
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Decrypt

OCI Vault: Decrypt

oracle/vault/decrypt · Action

Decrypt ciphertext with the master key that produced it, via the vault's crypto endpoint. Pass the base64 ciphertext returned by Encrypt; the recovered plaintext comes back base64-encoded.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… that encrypted the data
Ciphertext (base64)textRequiredThe base64 ciphertext returned by Encrypt

Returns: tool_result, plaintext, plaintext_checksum, key_id, success, error

03Encrypt

OCI Vault: Encrypt

oracle/vault/encrypt · Action

Encrypt data (≤ 4KB) with a master key via the vault's crypto endpoint. The plaintext must be base64-encoded; the ciphertext returns base64-encoded — feed it to Decrypt to recover the data. For larger data, use Generate Data Encryption Key.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… to encrypt with
Plaintext (base64)textRequiredThe data to encrypt, base64-encoded (≤ 4KB)

Returns: tool_result, ciphertext, key_id, success, error

04Export

OCI Vault: Export Key

oracle/vault/export_key · Action

Wrap and export a master key's material via the vault's crypto endpoint. The key must have been created exportable. Supply your own RSA wrapping public key (PEM); the material returns encrypted with it, so only the matching private key can unwrap it. RSA_OAEP_AES_SHA256 uses AES key-wrap; RSA_OAEP_SHA256 wraps the material directly.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… to export (must be exportable)
Wrapping Public Key (PEM)textRequiredYour 2048/3072/4096-bit RSA public key — full PEM, incl. BEGIN/END lines
Wrapping AlgorithmstringRequiredRSA_OAEP_AES_SHA256 or RSA_OAEP_SHA256 — choices: RSA-OAEP AES (SHA-256), RSA-OAEP (SHA-256)

Returns: tool_result, encrypted_key, key_version_id, success, error

05Generate

OCI Vault: Generate Data Encryption Key

oracle/vault/generate_data_encryption_key · Action

Generate a data encryption key (DEK) under a master key, via the vault's crypto endpoint — for envelope encryption of larger data. The DEK returns wrapped (encrypted) with the master key as the ciphertext; the plaintext DEK is included only when Include Plaintext Key is on.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… the master key to wrap the DEK with
AlgorithmstringAES (default), RSA or ECDSA — choices: AES (symmetric), RSA, ECDSA
Length (bytes)stringOptional — AES 16/24/32 (default 32); RSA 256/384/512 (default 256)
Include Plaintext KeybooleanAlso return the DEK unencrypted (default true)

Returns: tool_result, ciphertext, plaintext, plaintext_checksum, success, error

06Key

OCI Vault: Back Up Key

oracle/vault/key_backup · Action

Back up an Oracle Cloud master encryption key (resolved via the vault's management endpoint) to an Object Storage bucket or a pre-authenticated URI.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Key OCIDstringRequiredocid1.key.oc1..aaaa… to back up
Bucket NamespacestringObject Storage namespace holding the destination bucket
Bucket NamestringDestination bucket for the backup
Object NamestringOptional object name for the backup (OCI names it if blank)
Backup URIstringPre-authenticated request URI (alternative to a bucket)

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Cancel Key Deletion

oracle/vault/key_cancel_deletion · Action

Cancel a scheduled deletion of an Oracle Cloud master encryption key (resolved via the vault's management endpoint), restoring it from pending-deletion.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… that holds the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… to cancel deletion for

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Move Key to Compartment

oracle/vault/key_change_compartment · Action

Move an Oracle Cloud master encryption key (resolved via its vault's management endpoint) into a different compartment.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… holding the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… to move
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… to move the key into

Returns: tool_result, id, destination_compartment_id, success, error

OCI Vault: Create Key

oracle/vault/key_create · Action

Create a master encryption key in an Oracle Cloud vault — used to encrypt/decrypt data and protect secrets. Pick the algorithm (AES/RSA/ECDSA); for ECDSA choose the curve. Defaults to a SOFTWARE-protected key; poll Get Key until ENABLED.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Display NamestringRequiredA friendly name for the key
AlgorithmstringAES (default), RSA or ECDSA — choices: AES (symmetric), RSA, ECDSA
Curve (ECDSA only)stringThe elliptic curve for ECDSA keys — default NIST_P256 — choices: NIST P-256, NIST P-384, NIST P-521
Length (bytes)stringOptional — AES 16/24/32 (default 32); RSA 256/384/512 (default 256); ECDSA is set by the curve
Protection ModestringSOFTWARE (default) or HSM — choices: Software, HSM
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Disable Key

oracle/vault/key_disable · Action

Disable a master encryption key in an Oracle Cloud vault so it can no longer encrypt, decrypt, or protect secrets until re-enabled. Resolved via the vault's management endpoint.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to disable

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Enable Key

oracle/vault/key_enable · Action

Re-enable a disabled master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint), returning it to the ENABLED state so it can be used again.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to enable

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Get Key

oracle/vault/key_get · Action

Fetch a single master encryption key from an Oracle Cloud vault by its OCID (resolved via the vault's management endpoint).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to fetch

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: List Keys

oracle/vault/key_list · Action

List the master encryption keys in an Oracle Cloud vault (resolved via the vault's management endpoint), in a compartment. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… to list keys from

Returns: tool_result, keys, count, truncated, success, error

OCI Vault: Restore Key

oracle/vault/key_restore · Action

Restore a master encryption key into an Oracle Cloud vault from an Object Storage backup (a bucket or a pre-authenticated URI). Creates a new key.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… of the vault to restore the key into
Bucket NamespacestringObject Storage namespace holding the backup
Bucket NamestringBucket holding the key backup
Object NamestringObject name of the key backup within the bucket
Backup URIstringPre-authenticated request URI (alternative to a bucket)

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Schedule Key Deletion

oracle/vault/key_schedule_deletion · Action

Schedule a master encryption key in an Oracle Cloud vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first. Resolved via the vault's management endpoint.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to schedule for deletion
Time of Deletion (RFC3339)stringe.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Update Key

oracle/vault/key_update · Action

Update a master encryption key in an Oracle Cloud vault — change its display name and/or replace its freeform tags (resolved via the vault's management endpoint).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… the key lives in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to update
Display NamestringA new friendly name for the key (optional)
Freeform Tags (JSON)string{"env":"prod"} — replaces existing tags (optional)

Returns: tool_result, key, id, lifecycle_state, success, error

OCI Vault: Cancel Key Version Deletion

oracle/vault/key_version_cancel_deletion · Action

Cancel a pending deletion of a key version in an Oracle Cloud vault (resolved via the vault's management endpoint), returning it to an enabled state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… holding the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… the version belongs to
Key Version OCIDstringRequiredocid1.keyversion.oc1..aaaa… to cancel deletion for

Returns: tool_result, key_version, id, lifecycle_state, success, error

OCI Vault: Create Key Version

oracle/vault/key_version_create · Action

Create a new key version for a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint), rotating the key's active material.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… holding the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… to create a new version for

Returns: tool_result, key_version, id, lifecycle_state, success, error

OCI Vault: Get Key Version

oracle/vault/key_version_get · Action

Fetch a single key version of a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… holding the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… whose version to fetch
Key Version OCIDstringRequiredocid1.keyversion.oc1..aaaa… to fetch

Returns: tool_result, key_version, id, lifecycle_state, success, error

OCI Vault: List Key Versions

oracle/vault/key_version_list · Action

List the versions of a master encryption key in an Oracle Cloud vault (resolved via the vault's management endpoint). Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… holding the key
Key OCIDstringRequiredocid1.key.oc1..aaaa… to list versions of

Returns: tool_result, key_versions, count, truncated, success, error

OCI Vault: Schedule Key Version Deletion

oracle/vault/key_version_schedule_deletion · Action

Schedule a specific version of an Oracle Cloud master key for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Key OCIDstringRequiredocid1.key.oc1..aaaa…
Key Version OCIDstringRequiredocid1.keyversion.oc1..aaaa…
Time of Deletion (RFC3339)stringe.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days

Returns: tool_result, key_version, id, lifecycle_state, success, error

07Secret

OCI Vault: Get Secret Bundle

oracle/vault/secret_bundle_get · Action

Retrieve the contents of a secret (its base64-encoded value plus version metadata) from an Oracle Cloud vault. Defaults to the current version; pass a version number or stage (CURRENT/PENDING/LATEST/PREVIOUS/DEPRECATED) to fetch a specific one.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the secret picker)
Vault OCIDstringocid1.vault.oc1..aaaa… (scopes the secret picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… to retrieve
Version NumberstringA specific version number (optional; defaults to current)
StagestringCURRENT (default), PENDING, LATEST, PREVIOUS or DEPRECATED — choices: Current, Pending, Latest, Previous, Deprecated

Returns: tool_result, content, version_number, version_name, secret_id, success, error

OCI Vault: Get Secret Bundle by Name

oracle/vault/secret_bundle_get_by_name · Action

Retrieve the contents of a secret (its base64-encoded value plus version metadata) by the secret's name within an Oracle Cloud vault. Defaults to the current version; pass a version number or stage (CURRENT/PENDING/LATEST/PREVIOUS/DEPRECATED) to fetch a specific one.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the secret picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… that contains the secret
Secret NamestringRequiredThe secret's name (unique within the vault, case-sensitive)
Version NumberstringA specific version number (optional; defaults to current)
StagestringCURRENT (default), PENDING, LATEST, PREVIOUS or DEPRECATED — choices: Current, Pending, Latest, Previous, Deprecated

Returns: tool_result, content, version_number, version_name, secret_id, success, error

OCI Vault: List Secret Bundle Versions

oracle/vault/secret_bundle_versions_list · Action

List all bundle versions of a secret in an Oracle Cloud vault — each version's number, name, rotation stages and creation time — from the secrets-retrieval endpoint. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the secret picker)
Vault OCIDstringocid1.vault.oc1..aaaa… (scopes the secret picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… whose versions to list

Returns: tool_result, versions, count, truncated, success, error

OCI Vault: Cancel Secret Deletion

oracle/vault/secret_cancel_deletion · Action

Cancel a pending secret deletion in an Oracle Cloud vault, returning the secret to ACTIVE before its scheduled deletion time elapses.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… whose pending deletion to cancel

Returns: tool_result, secret, id, lifecycle_state, success, error

OCI Vault: Move Secret to Compartment

oracle/vault/secret_change_compartment · Action

Move a secret from its current compartment into another compartment within the same Oracle Cloud tenancy.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… to move
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… to move the secret into

Returns: tool_result, id, destination_compartment_id, success, error

OCI Vault: Create Secret

oracle/vault/secret_create · Action

Store a new secret in an Oracle Cloud vault, encrypted under a master key. The content must be base64-encoded. Poll Get Secret until ACTIVE, then retrieve it with Get Secret Bundle.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… to store the secret in
Key OCIDstringRequiredocid1.key.oc1..aaaa… to encrypt the secret with
Secret NamestringRequiredUnique name within the vault (letters, numbers, hyphens)
Secret Content (base64)textRequiredThe secret value, base64-encoded
DescriptionstringWhat this secret is for (optional)
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, secret, id, lifecycle_state, success, error

OCI Vault: Get Secret

oracle/vault/secret_get · Action

Fetch a secret's metadata by OCID (name, vault, key, current version, lifecycle state). Does not return the secret value — use Get Secret Bundle for that.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… to fetch

Returns: tool_result, secret, id, lifecycle_state, success, error

OCI Vault: List Secrets

oracle/vault/secret_list · Action

List the secrets in an Oracle Cloud compartment, optionally filtered to a single vault and/or an exact secret name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Vault OCIDstringocid1.vault.oc1..aaaa… to filter to (optional)
Secret NamestringFilter to an exact secret name (optional)

Returns: tool_result, secrets, count, truncated, success, error

OCI Vault: Schedule Secret Deletion

oracle/vault/secret_schedule_deletion · Action

Schedule the deletion of a secret in an Oracle Cloud vault — OCI removes it at the chosen time (or the earliest permissible time if none is given), and it stays cancellable until then.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the secret picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… to schedule for deletion
Time of Deletion (RFC3339)stringe.g. 2026-08-01T00:00:00Z — leave blank for the earliest permissible time (optional)

Returns: tool_result, id, success, error

OCI Vault: Update Secret

oracle/vault/secret_update · Action

Update an Oracle Cloud secret's description or tags, and optionally set new base64-encoded content — which creates a new secret version.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… of the secret to update
Secret Content (base64)textNew secret value, base64-encoded — sets a new version (optional)
DescriptionstringWhat this secret is for (optional)
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, secret, id, lifecycle_state, success, error

OCI Vault: Cancel Secret Version Deletion

oracle/vault/secret_version_cancel_deletion · Action

Cancel a pending deletion of a single secret version in an Oracle Cloud vault, returning it to the secret before its scheduled deletion time elapses.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… the version belongs to
Version NumberstringRequiredThe secret version number whose pending deletion to cancel

Returns: tool_result, secret_version, success, error

OCI Vault: Get Secret Version

oracle/vault/secret_version_get · Action

Fetch the metadata for one version of a secret — its stages, content type and creation time. This is version metadata, not the secret value; retrieve the content with Get Secret Bundle.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… whose version to fetch
Version NumberstringRequiredThe version number, a whole number (e.g. 1)

Returns: tool_result, secret_version, success, error

OCI Vault: List Secret Versions

oracle/vault/secret_version_list · Action

List the versions of a single Oracle Cloud vault secret, newest first, showing each version's number, rotation stages and creation time. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… to list versions of

Returns: tool_result, versions, count, truncated, success, error

OCI Vault: Schedule Secret Version Deletion

oracle/vault/secret_version_schedule_deletion · Action

Schedule a specific version of a secret in an Oracle Cloud vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Secret OCIDstringRequiredocid1.vaultsecret.oc1..aaaa… whose version to schedule for deletion
Version NumberstringRequiredThe version number, a whole number (e.g. 1)
Time of Deletion (RFC3339)stringe.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days

Returns: tool_result, secret_version, id, version_number, success, error

08Sign

OCI Vault: Sign

oracle/vault/sign · Action

Sign a message (or its digest) with a master key via the vault's crypto endpoint. The message must be base64-encoded (≤ 4KB); the signature returns base64-encoded — verify it with Verify. For large data, hash it and sign the DIGEST.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… to sign with (RSA or ECDSA)
Message (base64)textRequiredThe message or digest to sign, base64-encoded (≤ 4KB)
Signing AlgorithmstringRequiredMatch the key type (RSA or ECDSA) and the digest's hash — choices: SHA-224 RSA PKCS PSS, SHA-256 RSA PKCS PSS, SHA-384 RSA PKCS PSS, SHA-512 RSA PKCS PSS, SHA-224 RSA PKCS1 v1.5, SHA-256 RSA PKCS1 v1.5, SHA-384 RSA PKCS1 v1.5, SHA-512 RSA PKCS1 v1.5, ECDSA SHA-256, ECDSA SHA-384, ECDSA SHA-512
Message TypestringRAW (default) or DIGEST — choices: Raw message, Message digest

Returns: tool_result, signature, key_version_id, success, error

09Vault

OCI Vault: Back Up Vault

oracle/vault/vault_backup · Action

Back up an Oracle Cloud Vault (optionally including its keys) to an Object Storage bucket or a pre-authenticated URI.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Bucket NamespacestringObject Storage namespace holding the destination bucket
Bucket NamestringDestination bucket for the backup
Object NamestringOptional object name for the backup (OCI names it if blank)
Backup URIstringPre-authenticated request URI (alternative to a bucket)
Include KeysbooleanInclude the vault's keys in the backup (default true)

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Cancel Vault Deletion

oracle/vault/vault_cancel_deletion · Action

Cancel a scheduled deletion of an Oracle Cloud Vault, restoring it to its active state.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Move Vault to Compartment

oracle/vault/vault_change_compartment · Action

Move an Oracle Cloud Vault into a different compartment by OCID.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… — the compartment to move the vault to

Returns: tool_result, id, destination_compartment_id, success, error

OCI Vault: Create Vault

oracle/vault/vault_create · Action

Create an Oracle Cloud Vault — the container for master encryption keys and secrets. A DEFAULT vault is shared, VIRTUAL_PRIVATE is dedicated. Returns the OCID immediately in a CREATING state; poll Get Vault until ACTIVE.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)
Display NamestringRequiredA friendly name for the vault
Vault TypestringDEFAULT (shared) or VIRTUAL_PRIVATE (dedicated) — choices: Default (shared), Virtual Private (dedicated)
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Create Vault Replica

oracle/vault/vault_create_replica · Action

Replicate an Oracle Cloud Vault into another region in the same realm — an asynchronous operation.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Replica RegionstringRequirede.g. uk-cardiff-1

Returns: tool_result, id, replica_region, success, error

OCI Vault: Delete Vault Replica

oracle/vault/vault_delete_replica · Action

Remove a cross-region replica of an Oracle Cloud Vault — asynchronous; OCI tears the replica down in the background.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Replica RegionstringRequiredThe region whose replica to remove, e.g. uk-cardiff-1

Returns: tool_result, id, replica_region, success, error

OCI Vault: Get Vault

oracle/vault/vault_get · Action

Fetch a single Oracle Cloud Vault by OCID — its type, lifecycle state, and its management and crypto endpoints.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Get Vault Usage

oracle/vault/vault_get_usage · Action

Report how many keys and key versions a Vault holds — HSM and software counts, across all compartments (excluding deleted).

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…

Returns: tool_result, key_count, key_version_count, software_key_count, software_key_version_count, success, error

OCI Vault: List Vaults

oracle/vault/vault_list · Action

List the Oracle Cloud Vaults in a compartment. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root)

Returns: tool_result, vaults, count, truncated, success, error

OCI Vault: List Vault Replicas

oracle/vault/vault_list_replicas · Action

List the cross-region replicas of an Oracle Cloud Vault. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…

Returns: tool_result, replicas, count, truncated, success, error

OCI Vault: Restore Vault

oracle/vault/vault_restore · Action

Restore an Oracle Cloud Vault from an Object Storage backup into a new vault — supply either the bucket location (namespace, bucket, object) or a pre-authenticated request URI. Returns the OCID immediately; poll Get Vault until ACTIVE.

FieldTypeDetails
Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… (the compartment to restore the vault into)
Bucket NamespacestringObject Storage namespace holding the backup (with bucket + object)
Bucket NamestringBucket that holds the backup object (with namespace + object)
Object NamestringName of the backup object in the bucket (with namespace + bucket)
Backup PAR URIstringPre-authenticated request URI to the backup (alternative to the bucket fields)

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Schedule Vault Deletion

oracle/vault/vault_schedule_deletion · Action

Schedule an Oracle Cloud Vault for deletion — it moves to pending-deletion and is removed at the chosen time (7–30 days out; 30 days by default) unless cancelled first.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Time of Deletion (RFC3339)stringe.g. 2026-08-15T00:00:00Z — 7–30 days out; leave blank for 30 days

Returns: tool_result, vault, id, lifecycle_state, success, error

OCI Vault: Update Vault

oracle/vault/vault_update · Action

Update an Oracle Cloud Vault's display name and/or its free-form tags, addressed by OCID.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa…
Display NamestringA new, human-friendly name for the vault (optional)
Free-form TagsstringReplaces all free-form tags, e.g. {"env":"prod"} (optional)

Returns: tool_result, vault, id, lifecycle_state, success, error

10Verify

OCI Vault: Verify Signature

oracle/vault/verify · Action

Verify a cryptographic signature against a message via the vault's crypto endpoint. Provide the base64 message (or its digest), the base64 signature, and the same key, signing algorithm and message type that produced it. Returns is_valid true or false.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the vault/key pickers)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… (its crypto endpoint is used)
Key OCIDstringRequiredocid1.key.oc1..aaaa… that signed the message
Message (base64)textRequiredThe base64-encoded message, or its digest (≤ 4KB)
Signature (base64)textRequiredThe base64-encoded signature to verify
Signing AlgorithmstringRequiredThe algorithm that produced the signature — choices: SHA-224 RSA PKCS#1 v1.5, SHA-256 RSA PKCS#1 v1.5, SHA-384 RSA PKCS#1 v1.5, SHA-512 RSA PKCS#1 v1.5, SHA-224 RSA PSS, SHA-256 RSA PSS, SHA-384 RSA PSS, SHA-512 RSA PSS, ECDSA SHA-256, ECDSA SHA-384, ECDSA SHA-512
Message TypestringRAW (default) or DIGEST — choices: Raw message, Message digest

Returns: tool_result, is_valid, success, error

11Wrapping

OCI Vault: Get Wrapping Key

oracle/vault/wrapping_key_get · Action

Fetch an Oracle Cloud vault's RSA wrapping key (resolved via the vault's management endpoint) — use its public key to wrap external key material before importing it with Import Key.

FieldTypeDetails
Compartment OCIDstringocid1.compartment.oc1..aaaa… (scopes the picker)
Vault OCIDstringRequiredocid1.vault.oc1..aaaa… to fetch the wrapping key for

Returns: tool_result, public_key, id, lifecycle_state, success, error

12Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Key and crypto operations run against each vault's own management and crypto endpoints, whose DNS can lag a few minutes behind the vault first reporting ACTIVE, so calls against a freshly created vault may fail briefly with a "still provisioning" message until the endpoint resolves.
  • Get Secret returns only a secret's metadata (name, vault, key, current version and lifecycle state); the value itself is retrieved separately with Get Secret Bundle or Get Secret Bundle by Name, which return it base64-encoded.
  • Vaults, keys and key versions cannot be deleted immediately — deletion is scheduled 7 to 30 days out (30 days by default) and stays cancellable until that time elapses, while secret deletions are likewise staged and remain reversible until their scheduled time.
  • Create and restore actions for vaults, keys and secrets return an OCID in a provisioning state, so poll Get Vault, Get Key or Get Secret until the resource reaches ACTIVE or ENABLED before using it.
  • Encrypt, Sign and Verify accept at most 4 KB of base64-encoded input; for larger payloads use Generate Data Encryption Key for envelope encryption, or hash the data and sign the digest.
  • Export Key succeeds only on a key that was created as exportable, and that capability cannot be added to an existing key afterwards.