Connect your own CyberArk Privileged Access Manager (PVWA) to manage Safes, privileged Accounts, credential retrieval/rotation, Just-In-Time access requests, and Applications, plus review Security...
What this app can do
26 tools registered
Connect CyberarkFree
Connect your own CyberArk PVWA vault by saving its base URL and credentials, after checking they actually work.
Disconnect CyberarkFree
Disconnect a CyberArk vault: deletes only the saved credentials. Nothing in CyberArk itself is changed.
List ConnectionsFree
List the connected CyberArk vaults.
Audit Vault40 tok
Build one aggregated health report for the connected CyberArk vault: Safe count, Account count, and pending access requests.
List Safes8 tok
List Safes in the connected CyberArk vault, optionally filtered by a search string.
Get Safe8 tok
Read one CyberArk Safe in full.
Create Safe16 tok
Create a new Safe in the connected CyberArk vault.
List Safe Members8 tok
List the members (users/groups with access) of a CyberArk Safe.
Add Safe Member16 tok
Grant a user or group access to a CyberArk Safe.
List Accounts8 tok
List privileged Accounts in the connected CyberArk vault, optionally filtered by a search string or Safe name.
Get Account8 tok
Read one privileged Account's metadata in full (never the secret itself -- use retrieve_account_password for that).
Create Account16 tok
Onboard a new privileged Account into a Safe.
Update Account16 tok
Update selected fields of an existing Account (name, address). Only given fields change.
Delete Account20 tok
Permanently delete a privileged Account from CyberArk. Cannot be undone.
Retrieve Account Password16 tok
Retrieve a privileged Account's current password/secret. This exposes real credentials -- use with care.
Verify Account Password16 tok
Verify a privileged Account's stored password still matches the target system (CyberArk's own reconciliation check).
Reconcile Account Password16 tok
Force-reconcile a privileged Account's password using its Safe's configured reconciliation account -- use after a manual out-of-band change desynced the vault.
Change Account Password16 tok
Rotate a privileged Account's password immediately (CPM-managed or explicit new value). This changes the real credential in the target system.
Create Access Request16 tok
Create a Just-In-Time access request for a privileged Account -- for Safes configured with dual control, this must be confirmed before retrieval succeeds.
List Access Requests8 tok
List Just-In-Time access requests for a privileged Account.
Confirm Access Request16 tok
Confirm a pending Just-In-Time access request on a dual-control Safe -- required from a second approver before the requestor can retrieve the credential.
Cancel Access Request16 tok
Cancel a pending Just-In-Time access request before it is confirmed or used.
List Applications8 tok
List AAM/CCP Application identities configured on the connected CyberArk vault -- the programmatic identities that can fetch credentials without a human.
Get Application8 tok
Read one AAM/CCP Application identity in full.
List Platforms8 tok
List account-type Platforms (templates) configured on the connected CyberArk vault, e.g. 'WinServerLocal', 'UnixSSH' -- required when onboarding a new Account.
List Security Events8 tok
Read the Security Events audit trail for the connected CyberArk vault -- who accessed or changed what, and when.