Skip to content

Effective secrets for a component

GET
/components/{name}/effective-secrets
curl --request GET \
--url https://example.com/api/v1/components/example/effective-secrets

Resolves the secrets that cascade onto a component (platform -> location -> component), with the winner and the shadowed candidates it overrode. There is NO system band: a secret is device-facing, and the room a component happens to serve is the wrong owner for a credential the device itself answers with. Fields are masked, as in the directory; plaintext is only ever the audited reveal. Gated by secret:read, which the viewer floor does not carry, and admin-sensitive secrets appear only to the admin tier.

name
required

The component’s name

string

The component’s name

OK

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
secrets
required
Array<object> | null
object
band
required

Cascade tier: 0 platform, 1 location, 3 component

integer format: int64
depth
required

Distance up the tier’s tree from the component (0 nearest)

integer format: int64
fields
required
Array<object> | null
object
name
required
string
secret
required

Whether the field is encrypted at rest and masked here

boolean
value
required
string
id
required
string
name
required
string
owner_id

The owning entity’s id, the canonical handle; absent for a platform owner

string
owner_kind
required
string
owner_name
string
secret_type
required

The secret_type name

string
secret_type_id
required

The secret_type’s uuid

string
winner
required

True for the resolved secret; false for a shadowed candidate

boolean
Example
{
"$schema": "/api/v1/schemas/EffectiveSecretsOutputBody.json"
}

Error

Media type application/problem+json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
detail

A human-readable explanation specific to this occurrence of the problem.

string
errors

Optional list of individual error details

Array<object> | null
object
location

Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’

string
message

Error message text

string
value

The value at the given location

instance

A URI reference that identifies the specific occurrence of the problem.

string format: uri
status

HTTP status code

integer format: int64
title

A short, human-readable summary of the problem type. This value should not change between occurrences of the error.

string
type

A URI reference to human-readable documentation for the error.

string format: uri
default: about:blank
Example
{
"$schema": "/api/v1/schemas/ErrorModel.json",
"detail": "Property foo is required but is missing.",
"instance": "https://example.com/error-log/abc123",
"status": 400,
"title": "Bad Request",
"type": "about:blank"
}