Can AI agents automate CyberArk Privileged Access Manager Self-Hosted?
CyberArk · on-prem · identityenterprise
CyberArk Privileged Access Manager Self-Hosted is automatable today through its PVWA REST APIs. This record is the self-hosted Password Vault / PVWA edition. It is not Privilege Cloud. Opened docs title the product Privileged Access Manager - Self-Hosted and state that REST commands create, list, modify, and delete PAM entities from programs and scripts. APIs ship with PVWA. After Logon, every other call sends the session token in the Authorization header. The 2nd gen Logon paths are POST /PasswordVault/API/auth/Cyberark/Logon/, /Windows/Logon/, /LDAP/Logon/, and /RADIUS/Logon/; the default session is 20 minutes. GET /PasswordVault/API/Accounts lists vault accounts with search, filter, offset, and a 1000-row limit. POST /PasswordVault/API/Accounts adds a privileged account or SSH key when the caller has Add account permission. Swagger is at /PasswordVault/swagger. CyberArk recommends PACLI only when a REST method does not exist; PACLI INIT/LOGON/STOREFILE examples can prompt for a password. Material limits are an on-prem vault and PVWA, a license that must enable the APIs, short-lived session tokens, Safe-level permissions, and some vault tasks remaining PACLI-only. First-party MCP ownership is not established. Computer-use viability is unassessed. API scores 7 and is the best path because vendor docs present REST as the primary automation surface and PACLI as the fallback.
Best path today: api · Overall automatability: 7/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restsession-token coverage: partial · docs |
| SDK | unknown | official: unknown |
| MCP | unknown | verdict: unknown |
| Integrations | unknown | |
| CLI | yes | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: json · import: json | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. Documented machine paths are the PAM Self-Hosted REST APIs on PVWA and the PACLI command-line SDK. This record is CyberArk Privileged Access Manager Self-Hosted. It is not CyberArk Privilege Cloud and not HashiCorp Vault.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 7 | — | — | 5 | — | — | 7 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-13 |
vendor | declared | source | 2026-09-13 |
name | declared | source | 2026-09-13 |
deployment | declared | source | 2026-09-13 |
platforms[0] | declared | source | 2026-09-13 |
platforms[1] | declared | source | 2026-09-13 |
license | declared | source | 2026-09-13 |
status | declared | source | 2026-09-13 |
modalities.api.exists | declared | source | 2026-09-13 |
modalities.api.kinds[0] | declared | source | 2026-09-13 |
modalities.api.auth[0] | declared | source | 2026-09-13 |
modalities.api.auth[0] | declared | source | 2026-09-13 |
modalities.api.coverage | declared | source | 2026-09-13 |
modalities.api.coverage | declared | source | 2026-09-13 |
modalities.api.docs | declared | source | 2026-09-13 |
modalities.cli.exists | declared | source | 2026-09-13 |
modalities.data_access.export[0] | declared | source | 2026-09-13 |
modalities.data_access.import[0] | declared | source | 2026-09-13 |
modalities.rpa.ui_stack[0] | declared | source | 2026-09-13 |
modalities.agent_docs.llms_txt | scraped | source | 2026-09-13 |
modalities.mcp.first_party | declared | source | 2026-09-13 |
verdict.scores.api | declared | source | 2026-09-13 |
verdict.scores.cli | declared | source | 2026-09-13 |
freshness.watch[0].url | declared | source | 2026-09-13 |
freshness.watch[1].url | declared | source | 2026-09-13 |
freshness.watch[2].url | declared | source | 2026-09-13 |
freshness.watch[3].url | declared | source | 2026-09-13 |
Related tools
Other products in this database that share a category with CyberArk Privileged Access Manager Self-Hosted.
Last verified 2026-09-13 · volatility medium · JSON record