Skip to content

Reveal a secret's plaintext

POST
/secrets/{id}:reveal
curl --request POST \
--url https://example.com/api/v1/secrets/example:reveal

Decrypts and returns a secret’s field values, auditing the decrypt. Gated by secret:reveal at the caller’s scope; an admin-sensitive secret additionally needs the admin tier (secret:reveal:admin), so a scoped operator reveals device secrets but never a platform credential.

id
required

The secret’s id

string

The secret’s id

OK

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
fields
required

The decrypted field values, keyed by field name

object
key
additional properties
string
Example
{
"$schema": "/api/v1/schemas/RevealSecretOutputBody.json"
}

Error

Media type application/problem+json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
detail

A human-readable explanation specific to this occurrence of the problem.

string
errors

Optional list of individual error details

Array<object> | null
object
location

Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’

string
message

Error message text

string
value

The value at the given location

instance

A URI reference that identifies the specific occurrence of the problem.

string format: uri
status

HTTP status code

integer format: int64
title

A short, human-readable summary of the problem type. This value should not change between occurrences of the error.

string
type

A URI reference to human-readable documentation for the error.

string format: uri
default: about:blank
Example
{
"$schema": "/api/v1/schemas/ErrorModel.json",
"detail": "Property foo is required but is missing.",
"instance": "https://example.com/error-log/abc123",
"status": 400,
"title": "Bad Request",
"type": "about:blank"
}