AppRole is an authentication method in OpenBao designed for non‑interactive systems, such as automation tools, CI/CD pipelines, batch jobs, and backend services. It provides a secure way for applications to obtain a token without requiring human interaction or a browser‑based login.

AppRole is commonly used when workloads cannot use OIDC or Kubernetes authentication.

How AppRole Works

AppRole authentication is based on two components:

An application presents both values to OpenBao to obtain a token:
Codice
 

bao auth approle login role_id=<role-id> secret_id=<secret-id>

The returned token carries the policies assigned to the AppRole.


When to Use AppRole

AppRole is suitable for:


Creating an AppRole

AppRoles are created inside the tenancy namespace. The process consists of defining the role, assigning policies, and generating a SecretID.
 

1. Create the AppRole

Define the role and attach one or more policies: 

bao auth approle role write my-role \
  policies="my-policy"

You can attach multiple policies:

policies="policy-a,policy-b"

More details on creating policies: EWC Secret Manager - Policies
 

2. Retrieve the RoleID 

bao auth approle role-id read my-role

Output example:

role_id = "12345678-aaaa-bbbb-cccc-999999999999"

3. Generate a SecretID

bao auth approle secret-id generate my-role

Output example:

secret_id = "abcd1234-efgh5678-ijkl9012"

SecretIDs can be:

4. Log in using AppRole

Applications authenticate by presenting both values:
Codice
 

bao auth approle login \
  role_id="12345678-aaaa-bbbb-cccc-999999999999" \
  secret_id="abcd1234-efgh5678-ijkl9012"

The CLI or application receives a token with the policies assigned to the role.