vault
The vault built-in module is available only inside a PubNub Function. It reads secrets stored on the Function's keyset.
1const vault = require('vault');
Secrets are encrypted at rest and decrypted only during Function execution. Assign secrets from a Function's Package Revision editor (Assign secrets) or from the Keyset page of the Admin Portal.
get
get(secretKey)
* required
| Parameter | Description |
|---|---|
secretKey *Type: String | Name of the secret to retrieve. |
Returns: Promise resolving to the decrypted secret value. Rejects if the secret is missing.
1export default (request, response) => {
2 const xhr = require('xhr');
3 const vault = require('vault');
4
5 return vault.get('myApiKey').then((apiKey) => {
6 const http_options = {
7 method: 'GET',
8 headers: { API_KEY: apiKey }
9 };
10 return xhr.fetch('https://httpbin.org/get', http_options).then((resp) => {
11 return response.send('OK');
12 });
13 });
14};
Related reference
- Modules and libraries. Every built-in module available inside a Function.
- xhr. Making an authenticated outbound request with a retrieved secret.
- API limits. Per-execution vault read cap.