HashiCorp Vault
Integrate TigerIdentity with HashiCorp Vault for dynamic secret generation, unified policy management, and full secret access auditing.
Key features
Dynamic Secrets
Generate short-lived credentials for databases, cloud providers, and other systems on-demand.
Policy Sync
Sync Vault policies and ACLs into TigerIdentity for unified policy management.
Token Lifecycle
Track Vault token creation, renewal, and revocation across all authentication backends.
Secret Access Audit
Monitor who accesses which secrets and when, with complete audit trails.
Auto-Renewal
Automatically renew Vault tokens and dynamic credentials based on active sessions.
Just-In-Time Secrets
Request secrets only when needed, with automatic revocation after use.
Connect HashiCorp Vault in four steps.
Authenticate
Configure TigerIdentity with a Vault token or AppRole for API access.
Sync Configuration
TigerIdentity syncs Vault policies, auth methods, secret engines, and entities.
Stream Audit Logs
Enable Vault audit logging to send secret access events to TigerIdentity.
Generate Secrets
Request dynamic secrets through TigerIdentity with policy-based approvals.
Secrets Vault Integration
Real-time identity signals from HashiCorp Vault.
Every event, action, and change from HashiCorp Vault feeds the TigerIdentity policy engine and TIDR baseline in real time.
< 50 ms
Secrets Vault Integration
Configuration example
connector:
type: hashicorp-vault
name: "vault-production"
config:
address: "https://vault.company.com:8200"
token: "${VAULT_TOKEN}"
namespace: "production"
sync:
policies: true
auth_methods: true
secret_engines: true
entities: true
events:
audit_logs: true
stream_to_tiger: true
provisioning:
enabled: true
dynamic_secrets:
- database
- aws
- gcp
ttl: 3600
max_ttl: 28800Common use cases
Database Credentials
Generate short-lived database credentials on-demand, eliminating shared passwords.
Cloud Provider Secrets
Create temporary AWS/GCP/Azure credentials for specific tasks with automatic cleanup.
Secret Access Control
Enforce fine-grained policies on who can access which secrets under what conditions.
Break-Glass Scenarios
Provide emergency access to secrets with enhanced approval workflows and monitoring.
Ready to connect HashiCorp Vault?
See how TigerIdentity integrates with your HashiCorp Vault environment in a personalized demo.