Skip to content

Create a secret

POST
/secrets
curl --request POST \
--url https://example.com/api/v1/secrets \
--header 'Content-Type: application/json' \
--data '{ "admin_sensitive": true, "fields": { "additionalProperty": "example" }, "name": "example", "owner": "example", "owner_kind": "platform", "secret_type": "example" }'

Seals a secret at an owner scope. Fields are validated and encrypted against the type shape. Gated by secret:create, plus platform:create when owner_kind is platform (the install-wide tier).

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
admin_sensitive

Admin-only visibility; omit to use the type default. Setting true requires the admin tier

boolean
fields
required

The operator field map, validated against the type shape

object
key
additional properties
string
name
required

The cascade key; unique per owner

string
>= 1 characters
owner

The owning entity’s name; omit for a platform secret

string
owner_kind
required

Which tier owns this secret

string
Allowed values: platform location system component
secret_type
required

A secret_type id

string
>= 1 characters

Created

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
admin_sensitive
required

When true, only the admin tier may see or reveal this secret, regardless of placement

boolean
fields
required
Array<object> | null
object
name
required
string
secret
required

Whether the field is encrypted at rest and masked here

boolean
value
required
string
id
required
string
name
required
string
owner_id

The owning entity’s id, the canonical handle; absent for a global owner

string
owner_kind
required
string
owner_name
string
secret_type
required

The secret_type name

string
secret_type_id
required

The secret_type’s uuid, the stable form of secret_type

string
Example
{
"$schema": "/api/v1/schemas/SecretBody.json"
}

Error

Media type application/problem+json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
detail

A human-readable explanation specific to this occurrence of the problem.

string
errors

Optional list of individual error details

Array<object> | null
object
location

Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’

string
message

Error message text

string
value

The value at the given location

instance

A URI reference that identifies the specific occurrence of the problem.

string format: uri
status

HTTP status code

integer format: int64
title

A short, human-readable summary of the problem type. This value should not change between occurrences of the error.

string
type

A URI reference to human-readable documentation for the error.

string format: uri
default: about:blank
Example
{
"$schema": "/api/v1/schemas/ErrorModel.json",
"detail": "Property foo is required but is missing.",
"instance": "https://example.com/error-log/abc123",
"status": 400,
"title": "Bad Request",
"type": "about:blank"
}