Mints a scoped OpenBao token confined to secret/apps/<name>/* for an external app. The token is shown once — record it in the app immediately; it cannot be recovered later.
Give the external app this token (header X-Vault-Token) and the path convention below.
VAULT_ADDR=http://openbao:8200 path=secret/apps/<name>/conf curl "$VAULT_ADDR/v1/secret/data/apps//conf" \ -H "X-Vault-Token: <token above>"