List secret metadata
List names and metadata only. Secret values are never returned.
GET
/api/v2/secretsAuthorization
AuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
or
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
Header parameters
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
max length 128
Responses
200
Secret metadata returned; values are never exposed.
successbooleanrequiredAllowed:
truedataSecret[]requiredShow propertiesHide properties
Array of
Secretidstringrequirednamestringrequiredmatches ^[A-Z0-9_]+$
descriptionstring | nullrequiredallowedHostsstring[] | nullrequiredHosts this secret may be sent to. Null means any public host.
allowedPlacementsstring[] | nullrequiredWhere in the request this secret may appear. Null means anywhere.
lastUsedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredupdatedAtstring<date-time>required401
Unauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject403
Authenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject429
Too Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
