vault

The vault built-in module is available only inside a PubNub Function. It reads secrets stored on the Function's keyset.

1const vault = require('vault');

Secrets are encrypted at rest and decrypted only during Function execution. Assign secrets from a Function's Package Revision editor (Assign secrets) or from the Keyset page of the Admin Portal.

get​

get(secretKey)

* required
ParameterDescription
secretKey *
Type: String
Name of the secret to retrieve.

Returns: Promise resolving to the decrypted secret value. Rejects if the secret is missing.

1export default (request, response) => {
2 const xhr = require('xhr');
3 const vault = require('vault');
4
5 return vault.get('myApiKey').then((apiKey) => {
6 const http_options = {
7 method: 'GET',
8 headers: { API_KEY: apiKey }
9 };
10 return xhr.fetch('https://httpbin.org/get', http_options).then((resp) => {
11 return response.send('OK');
12 });
13 });
14};
  • Modules and libraries. Every built-in module available inside a Function.
  • xhr. Making an authenticated outbound request with a retrieved secret.
  • API limits. Per-execution vault read cap.

Was this page useful?

Last updated on