NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1076 most downloaded on NuGet
The most comprehensive .NET Library for HashiCorp's Vault which is a modern secret management system. * VaultSharp supports all Auth methods, all Secrets Engines and most System Apis supported by Vault. * VaultSharp has first class support for Consul and Enterpise Vault APIs etc. * Enterprise APIs like Control Groups, Transform Secrets Engine & KMIP Secrets Engine etc. This library is built with .NET Standard 2.0, .NET Standard 2.1, 4.6.2, 4.7.2*, 4.8, .NET 6, .NET 7 and .NET 8 and hence is cross-platform across .NET Core 2.x, 3.x, .NET Frameworks 4.x, Xamarin iOS, Android, Mac, UWP etc.
Last release 1 months ago
17 Aug 2026
Ships unpredictably
gaps range from 8 days to 1.9 years
Nearly every release is documented
notes for 52 of 53 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
55 releases · first in 2016
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BREAKING CHANGES:
NewBackendConfig class is removed and instead BackendConfig class has been enhanced.BUG FIXES:
readrole api due to ttl conversion issuesReadSecretPathsAsync allows empty path value to list all secrets on the mountPointFEATURES:
read ca chain ApiIMROVEMENTS:
PullNewSecretIdAsync allows for reponse wrapping using wrapTimeToLive parameterRemoveRootsFromChain field to SignCertificatesRequestOptionsReadSecretPathsAsync to use HTTP GET method and ?list=true instead of non-standard HTTP verb LISTlocal_secret_idsenterprise, echo_duration_ms, clock_skew_ms & replication_primary_canary_age_msOne column per quarter.
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BREAKING CHANGES:
IMROVEMENTS:
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
FEATURES:
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BREAKING CHANGES:
FEATURES:
IMPROVEMENTS:
[GH-269] Patch Secret Method updated to match API spec. PatchSecretDataRequest object with application/merge-patch+json will be sent as a HTTP PATCH R
BREAKING CHANGE:
PatchSecretDataRequest object with application/merge-patch+json will be sent as a HTTP PATCH Request.FEATURES:
DOC IMPROVEMENTS:
[GH-243] Fix the framework issue with TargetMoniker
IMPROVEMENTS:
DOC IMPROVEMENTS:
Add support for the `Terraform Cloud` Secret Backend
FEATURES:
Terraform Cloud Secret BackendIMPROVEMENTS:
orphaned tokens in create-token api, avoiding suod accessAs part of .NET Framework 4.6.x and 4.7.x and 4.8 support, the delegates to set `HttpClientHandler has changed to HttpMessagehandler`.
BREAKING CHANGES:
HttpClientHandler has changed to HttpMessagehandler.BUG FIXES:
WebRequestHandler with WinHttpHandlerIMPROVEMENTS:
WinHttpHandler instead of WebRequestHandler to support .NET 4.6 versions and higher.[GH-181] Transit Secret Engine respects a specific key version, that needs to be specified at the `EncryptionItem or RewrapItem` level.
BREAKING CHANGES:
EncryptionItem or RewrapItem level.Add support for `Key Management` Secrets Engine.
ENTERPRISE VAULT FEATURES:
Key Management Secrets Engine.BREAKING CHANGES:
[GH-131] Add support for `AliCloud` Secrets Engine.
FEATURES:
AliCloud Secrets Engine.Google Cloud KMS Secrets Engine.Identity Secrets Engine.MongoDBAtlas Secrets Engine.OpenLDAP Secrets Engine.ENTERPRISE VAULT FEATURES:
KMIP Secrets Engine.Transform Secrets Engine.BREAKING CHANGES:
GetSealStatusAsync doesn't throw an exception anymore for a sealed vault.IMPROVEMENTS:
X-Vault-Token header or as the standard Authorization: Bearer <vault-token> header.
By default, the Authorization: Bearer <vault-token> scheme is used.
You can override it using the VaultClientSettings.UseVaultTokenHeaderInsteadOfAuthorizationHeader flag.path field to FileAuditBackend class.performance_standby field to HealthStatus class.initialized, migration and recovery_seal fields to SealStatus class.options field to all the Backend classes.token_type field to all the BackendConfig classes.performance_standby and performance_standby_last_remote_wal fields to Leader class.otp and otp_length fields to RootTokenGenerationStatus class.TokenCapability class now returns additional fields as well other than the capabilities field.[GH-86] Fix the wrong default mount name for KV1 and KV2 secret engines. To minimize risks, please ensure you are using explicit mount points.
BREAKING CHANGES:
FEATURES:
BUG FIXES:
DOC IMPROVEMENTS:
[GH-74] Added support for .NET Standard 2.0 as well.
FEATURES:
Fixes default path of KeyValue version 1 to be kv.
BUG FIXES:
IAMAWSAuthMethodInfo class. Fixes [GH-61].DOC IMPROVEMENTS:
var in docs with type info, where the type is hard to infer.Fixes [GH-67] to read array of ca_chain instead of single string.
BUG FIXES:
Fixes [GH-61] to supply all the necessary values for IAM Auth login.
BUG FIXES:
Azure Secrets Engine: Add support for generating dynamic Azure credentials.
FEATURES:
Secrets Engine: Key Value: Version 1: Add support for Writing & Deleting of secrets.
FEATURES:
BREAKING CHANGES:
ReadSecretPathListAsync method name changes to ReadSecretPathsAsync. Apologies.Add support for Azure Auth method login.
FEATURES:
Add support for Azure Auth method login.
Add support for GoogleCloud Auth method login.
Add support for JWT/OIDC Auth method login.
Add support for Kubernetes Auth method login.
Add support for Okta Auth method login.
Add support for RADIUS Auth method login.
Transit Secrets Engine: Add support for Encrypt & Decrypt including Batched input.
Active Directory Secrets Engine: Add support for offering credentials.
AWS Secrets Engine: Add support for generating dynamic IAM credentials & STS IAM credentials.
Cubbhole Secrets Engine: Add support for read secret, read paths, write secret and delete secret APIs.
Database Secrets Engine: Add support for generating dynamic DB credentials.
GoogleCloud Secrets Engine: Add support for generating OAuth2 Token & Service Account Key.
Nomad Secrets Engine: Add support for generating dynamic credentials.
RabbitMQ Secrets Engine: Add support for generating dynamic credentials.
SSH Secrets Engine: Add support for generating dynamic credentials.
TOTP Secrets Engine: Add support for generating and validating TOTP code.
Supports .Net Standard 1.3 and .NET Framework 4.5. This enables supports for a wide range of platforms.
BREAKING CHANGES:
GenerateCredentialsAsync method name changes to GetCredentialsAsync. Apologies.Add support for PKI dynamic credentials.
FEATURES:
BREAKING CHANGES:
Secret Engines: Consul, KeyValue, PKI for dynamic credentials
FEATURES:
BREAKING CHANGES:
Add nonce to SealStatus type to allow seeing if the operation has reset. [https://github.com/hashicorp/vault/pull/2276/]
MISC:
DEPRECATIONS/CHANGES:
FEATURES:
IMPROVEMENTS:
SealStatus type to allow seeing if the operation has reset. [https://github.com/hashicorp/vault/pull/2276/]TransitEncryptAsyncBUG FIXES:
A major breaking change in VaultSharp 0.6.4 is STRONG NAMING of VaultSharp. Now both strong named and non-strong named assemblies can refer to VaultSh…
MISC:
DEPRECATIONS/CHANGES:
InitializeAsync method now takes a single container object for all parameters, instead of primitive parameters.
This single container object now has support for the additional recovery fields supported by Vault 0.6.2's initialization.path to file_path.MongoDbGenerateDynamicCredentialsAsync method now returns MongoDbUsernamePasswordCredentials instead of UsernamePasswordCredentials.
This ensures you get the database field back as well.MicrosoftSqlReadCredentialLeaseSettingsAsync method now returns the CredentialTimeToLiveSettings instead of the deprecated CredentialTtlSettings type.
This is in alignment with Vault deprecating ttl_max in favor of max_ttl.GetCallingTokenInfoAsync now returns a new response type CallingTokenInfo instead of the previous TokenInfo.
This supports the latest fields for Vault 0.6.4. [GH-18]TransitCreateEncryptionKeyAsync now supports the transitKeyType parameter to specify the type of key needed.TransitGetEncryptionKeyInfoAsync method now returns TransitEncryptionKeyInfo with a lot more fields like KeyDerivationFunction, ConvergentEncryptionVersion, etc.FEATURES:
/sys/wrapping Apis: Wrap, Rewrap, Lookup and Unwrap.UnwrapWrappedResponseDataAsync method also supports a generic return type to give you strongly typed data back.
So if you wrapped AWSCredentials, then you can unwrap Secret<AWSCredentials> instead of Secret<Dictionary<string, object>>.
And at any time if you need the non-generic method, you can always fallback to the non-generic version returning a dictionary.hmac_accessor, jsonx format etc.) for File and SysLog Audit Backends.AWSGenerateDynamicCredentialsWithSecurityTokenAsync method now supports the timeToLive parameter.Consul backend now supports the listing functionality to roles ConsulReadRoleListAsync. (https://github.com/hashicorp/vault/issues/2065)Transit backend now supports the new Apis for List of keys, Random, Hash, Digest, Sign, Verify etc.IMPROVEMENTS:
CassandraRoleDefinition now supports a consistency level parameter. (defaults to Quorum)MongoDbGenerateDynamicCredentialsAsync now returns the database name as well, related to the credentials.MySqlRoleDefinition now supports the RevocationSql parameter to revoke an user.RevocationSql parameter on the PostgreSqlRoleDefinition type to enable customization of user revocation SQL statements.BUG FIXES:
AppId backend is now deprecated, but still supported. Use AppRole instead.
MISC:
DEPRECATIONS/CHANGES:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
Added extensive XML documentation to the Apis.
IMPROVEMENTS:
This is a documentation-addition-only release; other than the version number there are no changes from 0.4.0.
Parity with Hashicorp's Vault 0.4.1 Api features
Nothing published for this version
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BUG FIXES:
/sys/health endpoint is only valid from the root namespace.Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BREAKING CHANGES:
IMPROVEMENTS:
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BUG FIXES:
[GH-223] Implemented support for Ed25519 Key type (Vault 1.9+ only)
IMPROVEMENTS:
[GH-235] Fix a deadlock when a particular internal path is chosen
BUG FIXES:
DOC IMPROVEMENTS:
IMPROVEMENTS: * .NET 6 Support
IMPROVEMENTS:
[GH-215] Certificate Auth now takes a chain of certificates.
IMPROVEMENTS:
The properties `IssuingCACertificateContent and CAChainContent of the base class AbstractCertificateData has been moved to a subclass AbstractIssuedCe
BREAKING CHANGES:
IssuingCACertificateContent and CAChainContent of the base class AbstractCertificateData has been moved to a subclass AbstractIssuedCertificateData.FEATURES:
IMPROVEMENTS:
Expiration in CertificateCredentials from int to long.Add support for `export-key api of Transit` Secret Engine
IMPROVEMENTS:
export-key api of Transit Secret Engine[GH-194] Transit's `ReadEncryptionKeyAsync returns the min_available_version and latest_version` of the key ring.
IMPROVEMENTS:
ReadEncryptionKeyAsync returns the min_available_version and latest_version of the key ring.VaultSharp now sets the `X-Vault-Request: true` header for all API calls.
IMPROVEMENTS:
X-Vault-Request: true header for all API calls.BUG FIXES:
ReadEncryptionKeyAsync for non aes256-gcm96 based key rings.[GH-192] Ability to sign certificate of PKI secret engine.
FEATURES:
[GH-187] Ability to customise the default Secret Engine MountPoints.
FEATURES:
Added active since timestamp to the status output of active nodes.
FEATURES:
BUG FIXES:
[GH-180] Fixes TOTP key list issue
BUG FIXES:
IMPROVEMENTS:
[Kerberos Auth]: Set pre-authenticate flag to optimize on dual calls.
IMPROVEMENTS:
DefaultCredentials instead of DefaultNetworkCredentials as the default credentials.[KV2 Secrets Engine]: Removed the redundant Dictionary based `WriteSecretAsync' method of KV2 engine. The generic method can be used for everything.
BREAKING CHANGES:
IMPROVEMENTS:
expires_at_seconds and token_ttl for OAuth2 Tokenttl for Service Account creation[GH-162] The CloudFoundryAuthMethodInfo constructor now takes the actual signature and date time
BREAKING CHANGES:
CloudFoundryAuthMethodInfo constructor now takes the actual signature and date timeFEATURES:
BUG FIXES:
WriteSecretAsync[GH-148] AWS.GenerateSTSCredentialsAsync() should use GET instead of POST.
BUG FIXES:
The KV2 Backend type changed from secret to kv-v2
BREAKING CHANGES:
secret to kv-v2FEATURES:
GenerateDataKey in Transit Engine.[GH-141] Ability to create, read and delete database roles. (non-static ones)
IMPROVEMENTS:
[GH-135] Fixed a bug with AWS Read Roles.
BUG FIXES:
[GH-135] Ability to inject custom `HttpClient` to VaultSharp.
IMPROVEMENTS:
HttpClient to VaultSharp.StorageType field to SealStatusDescription field to BackendConfig[GH-133] Add support for the optional `CertificateRoleName` while doing Cert based Auth.
IMPROVEMENTS:
CertificateRoleName while doing Cert based Auth.Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BUG FIXES:
ReadConnectionConfigAsync method uses the correct model object.GH-312 Fix `rotation_period` deserialization issues in System.Text.Json. And all such duration fields that Vault allows in string and integer form.
BUG FIXES:
rotation_period deserialization issues in System.Text.Json. And all such duration fields that Vault allows in string and integer form.Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BUG FIXES:
rotation_period deserialization issues in System.Text.Json. And all such duration fields that Vault allows in string and integer form.Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
Please see change log for full details: https://github.com/rajanadar/VaultSharp/blob/master/CHANGELOG.md
BREAKING CHANGES:
NewBackendConfig object instead of BackendConfig object.PullSecretIdAsync method is renamed to PullNewSecretIdAsyncReadRoleAsync method uses a new type AppRoleRoleModel instead of AppRoleInfo.GetCredentialsAsync method for assumed role changed the data type of Expiration field in AliCloudCredentials class from type string to DateTimeOffsetFullSecretMetadata object. No functional changes.FEATURES:
IMPROVEMENTS:
cas_required and custom_metadata in FullSecretMetadata class.Your coding agent can read these notes before it upgrades. Set up the MCP server →