> ## Documentation Index
> Fetch the complete documentation index at: https://hub.hcompany.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a vault

> Register a secrets provider for your organization.

Registers a [vault](/computer-use-agents/vaults/overview) (a link between your organization and an external secrets provider) so an agent can sign in to the sites it works on without you passing the secrets through the API. Today the only provider is [1Password](https://developer.1password.com/): you record which 1Password vault to read (`op_vault_id`) and a [service account token](https://www.1password.dev/service-accounts) that grants access to it.

The token is validated against the provider before it is stored, and is never returned by any endpoint.

Returns `201` with the created vault object (see [Retrieve](/computer-use-agents/vaults/retrieve) for the full field list).

<Warning>
  The request body carries a plaintext service account token. Send it only over HTTPS and never log it.
</Warning>

***

## Request body

<ParamField body="name" type="string" required>
  Human-readable label for the config.
</ParamField>

<ParamField body="provider_config" type="object" required>
  Provider settings.

  * `provider` (string, optional): Secrets provider. Defaults to `onepassword`, the only supported value.
  * `op_vault_id` (string, required): Identifier of the 1Password vault to read credentials from.
</ParamField>

<ParamField body="token" type="string" required>
  The 1Password service account token granting access to the vault. Write-only: validated before storage and omitted from every response.
</ParamField>

***

## Examples

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST https://agp.eu.hcompany.ai/api/v2/vaults \
    -H "Authorization: Bearer $HAI_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{
      "name": "prod-1password",
      "provider_config": {"provider": "onepassword", "op_vault_id": "abcd1234efgh5678"},
      "token": "ops_eyJ..."
    }'
  ```

  ```python Python theme={null}
  from hai_agents import Client, OnePasswordConfig

  client = Client()

  vault = client.vaults.create_vault(
      name="prod-1password",
      provider_config=OnePasswordConfig(op_vault_id="abcd1234efgh5678"),
      token="ops_eyJ...",
  )
  print(vault.id)
  ```

  ```typescript TypeScript theme={null}
  import { HaiAgentsClient } from "hai-agents";

  const client = new HaiAgentsClient();

  const vault = await client.vaults.createVault({
    name: "prod-1password",
    providerConfig: { opVaultId: "abcd1234efgh5678" },
    token: "ops_eyJ...",
  });
  console.log(vault.id);
  ```
</CodeGroup>

```json Response theme={null}
{
  "id": "f47ac10b-58cc-4372-a567-0e02b2c3d479",
  "org_id": "1c9a2f6e-4b3d-4a8c-9e5f-7d6b8a0c1e2f",
  "name": "prod-1password",
  "provider_config": {"provider": "onepassword", "op_vault_id": "abcd1234efgh5678"},
  "created_at": "2026-05-07T14:30:00Z",
  "updated_at": "2026-05-07T14:30:00Z"
}
```

***

## Errors

| Status | Cause                                                                                           |
| ------ | ----------------------------------------------------------------------------------------------- |
| `409`  | A vault with this `name` already exists in your organization. Names are unique per org.         |
| `422`  | Body failed validation, or the provider rejected the token (it could not access `op_vault_id`). |
