> ## Documentation Index
> Fetch the complete documentation index at: https://infisical.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create proxy

> Register an Agent Vault proxy and issue its one-time enrollment token



## OpenAPI

````yaml POST /api/v1/agent-vault/proxies
openapi: 3.0.3
info:
  title: Infisical API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
  - url: https://us.infisical.com
    description: Production server (US)
  - url: https://eu.infisical.com
    description: Production server (EU)
  - url: http://localhost:8080
    description: Local server
security: []
paths:
  /api/v1/agent-vault/proxies:
    post:
      tags:
        - Agent Vault Proxies
      description: Register an Agent Vault proxy and issue its one-time enrollment token
      operationId: createAgentVaultProxy
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 64
                  description: The name of the proxy.
                trafficPolicy:
                  type: string
                  enum:
                    - any-host
                    - bundle-hosts
                  description: >-
                    Which hosts an agent may reach through this proxy.
                    `any-host` lets every request out; `bundle-hosts` allows
                    only hosts an access bundle covers, plus anything in
                    `allowedHosts`, and refuses the rest with a 403.
                  default: any-host
                allowedHosts:
                  type: string
                  maxLength: 1024
                  nullable: true
                  description: >-
                    Hosts that stay reachable under the `bundle-hosts` traffic
                    policy even though no access bundle covers them. Still
                    intercepted, and given no credential.
                  default: null
                pollInterval:
                  type: integer
                  minimum: 10
                  maximum: 300
                  description: >-
                    How often, in seconds, the proxy refreshes its sessions and
                    settings. Between 10 and 300.
                  default: 60
              required:
                - name
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  proxy:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        description: The ID of the proxy.
                      name:
                        type: string
                        description: The name of the proxy.
                      heartbeat:
                        type: string
                        format: date-time
                        nullable: true
                        description: >-
                          When the proxy last checked in, or `null` if it never
                          has.
                      isHealthy:
                        type: boolean
                        description: >-
                          Whether the proxy has checked in recently enough to be
                          considered up.
                      rootCaFingerprint:
                        type: string
                        nullable: true
                        description: >-
                          The SHA-256 fingerprint of the proxy's certificate
                          authority. Pin this if you want to verify the proxy an
                          agent connects to.
                      rootCaExpiresAt:
                        type: string
                        format: date-time
                        nullable: true
                        description: When the proxy's certificate authority expires.
                      trafficPolicy:
                        type: string
                        enum:
                          - any-host
                          - bundle-hosts
                        description: >-
                          Which hosts an agent may reach through this proxy.
                          `any-host` lets every request out; `bundle-hosts`
                          allows only hosts an access bundle covers, plus
                          anything in `allowedHosts`, and refuses the rest with
                          a 403.
                      allowedHosts:
                        type: string
                        nullable: true
                        description: >-
                          Hosts that stay reachable under the `bundle-hosts`
                          traffic policy even though no access bundle covers
                          them. Still intercepted, and given no credential.
                      pollInterval:
                        type: number
                        description: >-
                          How often, in seconds, the proxy refreshes its
                          sessions and settings. Between 10 and 300.
                      createdAt:
                        type: string
                        format: date-time
                        description: When the proxy was registered.
                    required:
                      - id
                      - name
                      - heartbeat
                      - isHealthy
                      - rootCaFingerprint
                      - rootCaExpiresAt
                      - trafficPolicy
                      - allowedHosts
                      - pollInterval
                      - createdAt
                    additionalProperties: false
                    title: Admin view
                  token:
                    type: string
                    description: >-
                      A one-time token the proxy enrolls with. Shown once, and
                      valid for one hour.
                  expiresAt:
                    type: string
                    format: date-time
                required:
                  - proxy
                  - token
                  - expiresAt
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 422
                  message: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false

````