Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Create or rotate a secret

Store a new encrypted value or replace the existing value. The response contains metadata only.

PUT/api/v2/secrets/{name}
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Path parameters
namestringrequired

Uppercase secret name referenced by action templates.

min length 1 · max length 100 · matches ^[A-Z0-9_]+$
Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Request body
requiredapplication/json
valuestringrequired
min length 1 · max length 8192
descriptionstring
max length 500
allowedHostsstring[] | null

Hosts this secret may be sent to. A leading dot matches subdomains (".stripe.com" admits "api.stripe.com"). Null or omitted means any public host. Omitting it on a rotation leaves the existing value alone, so rotating a secret never widens where it may go.

max items 20
allowedPlacementsstring[] | null

Where in the request this secret may appear. Null or omitted means anywhere. A credential in a header is the intended use; the same value in a URL is usually a mistake or an exfiltration.

max items 3
Responses
200

Secret metadata returned; the value is never exposed.

successbooleanrequired
Allowed:true
dataSecretrequired

Secret metadata. The encrypted value is never exposed by any API.

Show properties
idstringrequired
namestringrequired
matches ^[A-Z0-9_]+$
descriptionstring | nullrequired
allowedHostsstring[] | nullrequired

Hosts this secret may be sent to. Null means any public host.

allowedPlacementsstring[] | nullrequired

Where in the request this secret may appear. Null means anywhere.

lastUsedAtstring<date-time> | nullrequired
createdAtstring<date-time>required
updatedAtstring<date-time>required
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
402

Payment Required - Usage quota exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X PUT 'https://api.anlyon.com/api/v2/secrets/string' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "value": "string",
  "description": "string",
  "allowedHosts": [
    "string"
  ],
  "allowedPlacements": [
    "url"
  ]
}'
Response
{
  "success": true,
  "data": {
    "id": "sec_01JABCDEF",
    "name": "string",
    "description": "string",
    "allowedHosts": [
      "string"
    ],
    "allowedPlacements": [
      "url"
    ],
    "lastUsedAt": "2019-08-24T14:15:22Z",
    "createdAt": "2019-08-24T14:15:22Z",
    "updatedAt": "2019-08-24T14:15:22Z"
  }
}