Create or rotate a secret
Store a new encrypted value or replace the existing value. The response contains metadata only.
/api/v2/secrets/{name}AuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
namestringrequiredUppercase secret name referenced by action templates.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
application/jsonvaluestringrequireddescriptionstringallowedHostsstring[] | nullHosts this secret may be sent to. A leading dot matches subdomains (".stripe.com" admits "api.stripe.com"). Null or omitted means any public host. Omitting it on a rotation leaves the existing value alone, so rotating a secret never widens where it may go.
allowedPlacementsstring[] | nullWhere in the request this secret may appear. Null or omitted means anywhere. A credential in a header is the intended use; the same value in a URL is usually a mistake or an exfiltration.
Secret metadata returned; the value is never exposed.
successbooleanrequiredtruedataSecretrequiredSecret metadata. The encrypted value is never exposed by any API.
Show propertiesHide properties
idstringrequirednamestringrequireddescriptionstring | nullrequiredallowedHostsstring[] | nullrequiredHosts this secret may be sent to. Null means any public host.
allowedPlacementsstring[] | nullrequiredWhere in the request this secret may appear. Null means anywhere.
lastUsedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredupdatedAtstring<date-time>requiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectPayment Required - Usage quota exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
