Use the /vault endpoint to store the credentials of your account, such as cloud storage credentials or a Play Store key. App Automation uses these credentials when it migrates settings from your template app to other apps, so you don’t need to send them with every request.
The data you store is encrypted. The API never returns it in plain text.
How it works
- Vault records belong to your account. Every app in the account can use them, and other accounts can’t read them.
- A record is identified by its
sectionandstore. Storing data for an existingsectionandstorecombination replaces the data of that record. - The API returns the
dataof each record in encrypted form only. Keep your own copy of the credentials if you need to check them later.
Sections that use the vault
The following app sections read credentials from the vault during a migration:
| Section | store | What to store in data | Used when |
|---|---|---|---|
csv_upload_settings | Omit | A JSON string with the credentials of your cloud storage. See CSV upload credentials. | The target app has no cloud storage credentials yet. Store exactly one record for this section. |
purchase_verification | google | The Play Store key, as a string. | The target app is an Android app. |
You can’t store data for the app_info and signature sections.
CSV upload credentials
For csv_upload_settings, data is a JSON string. Its content depends on the type of your storage.
Amazon S3
| Parameter | Data type | Required | Description |
|---|---|---|---|
type | String | Yes | Must be S3. |
bucket | String | Yes | Name of the bucket. |
key | String | Yes | Access key ID. |
secret | String | Yes | Secret access key. |
region | String | No | AWS region of the bucket. |
Google Cloud Storage
| Parameter | Data type | Required | Description |
|---|---|---|---|
type | String | Yes | Must be GCS. |
bucket | String | Yes | Name of the bucket. |
secret | Object | Yes | The service account key as a JSON object. |
Create or update a vault record
Store credentials for a section. If a record for the same section and store exists, its data is replaced.
API protocol
Endpoint: https://automate.adjust.com/app-automation/vault
Method: POST
Request body: Vault Create Request
Response: Vault Record
Example
Store Amazon S3 credentials for CSV upload
curl --location 'https://automate.adjust.com/app-automation/vault' \--header 'Authorization: Bearer {your-adjust-api-token}' \--header 'Content-Type: application/json' \--data '{ "section": "csv_upload_settings", "data": "{\"type\": \"S3\", \"bucket\": \"my-export-bucket\", \"key\": \"{access-key-id}\", \"secret\": \"{secret-access-key}\", \"region\": \"eu-central-1\"}"}'{ "id": 1, "account_id": 12345, "section": "csv_upload_settings", "store": null, "data": "{encrypted-data}", "created_at": "2026-10-01T09:30:00"}Store a Play Store key for purchase verification
curl --location 'https://automate.adjust.com/app-automation/vault' \--header 'Authorization: Bearer {your-adjust-api-token}' \--header 'Content-Type: application/json' \--data '{ "section": "purchase_verification", "store": "google", "data": "{play-store-key}"}'Errors
| Status code | Description |
|---|---|
400 | The section isn’t supported. You can’t store data for app_info or signature. |
422 | The request body is invalid. For example, section or store has an unknown value, or data is missing. |
Get vault records
Retrieve all vault records of your account. The data of each record is encrypted.
API protocol
Endpoint: https://automate.adjust.com/app-automation/vault
Method: GET
Response: Array of Vault Record
Example
curl --location 'https://automate.adjust.com/app-automation/vault' \--header 'Authorization: Bearer {your-adjust-api-token}'[ { "id": 1, "account_id": 12345, "section": "csv_upload_settings", "store": null, "data": "{encrypted-data}", "created_at": "2026-10-01T09:30:00" }, { "id": 2, "account_id": 12345, "section": "purchase_verification", "store": "google", "data": "{encrypted-data}", "created_at": "2026-10-01T09:32:00" }]Data models
Vault Create Request
| Parameter | Data type | Description |
|---|---|---|
section* | String | The app section the credentials are for. app_info and signature aren’t supported. |
store | String | The store the credentials are for. One of: google, itunes. Omit it if the credentials aren’t store-specific. |
data* | String | The credentials to store. The API encrypts the value before saving it. |
Vault Record
| Parameter | Data type | Description |
|---|---|---|
id* | Integer | Record ID. |
account_id* | Integer | ID of the account the record belongs to. |
section* | String | The app section the credentials are for. |
store | String | The store the credentials are for: google or itunes. null if not set. |
data* | String | The stored credentials in encrypted form. The API never returns plain text. |
created_at* | String | ISO datetime when the record was created. |