Skip to main content
A secret is a named value, such as an API key or a login, stored encrypted in your workspace. Its id is sec_ plus 16 letters and digits. The dashboard lists secrets on the Keychain page in settings. For how runs use a secret, see Secrets. A secret has no lifecycle states. It exists until its owner or a workspace admin deletes it.

Fields

List returns the base fields. Get, create, update, replace and transfer return the base fields plus the detail fields. No response except a reveal carries a value.
string
required
Always secret.
string
required
The secret id, sec_….
string
required
Unique in the workspace. 1 to 80 characters.
string
required
The type: api_key, login, identity or custom.
string
Up to 500 characters. Null when not set.
string[]
required
The HTTPS hosts the secret is meant for. Each URL names one exact host, with no wildcard. Can be empty, except for api_key.
string
Eight asterisks plus the last 4 characters of the first password field, or of the first field. Null when that value is shorter than 4 characters.
object[]
required
One entry per field, with labels and types only.
object
required
Who created the secret: type (user or agent), id and label.
object
The owning person: id and name. Null when an agent created the secret.
string
required
private, company or custom. Defaults to company.
integer
required
How many grants name this secret.
string
When a person last revealed the value. Null until the first reveal.
string
required
ISO 8601 timestamp.
string
required
ISO 8601 timestamp.
object[]
Detail only. Like fieldSummary, plus required.
string
Detail only. When the fields were last replaced. Null until the first replace.
string
Detail only. When the value was last revealed. Null until the first reveal.
object
Only on get with expand[]=grants. A list of up to 25 grants, newest first, with hasMore and totalCount.
A reveal returns a different object:
string
required
Always secret_value.
string
required
The secret id, sec_….
object[]
required
One entry per field: label, type and the decrypted value.
string
required
When the reveal happened.

Who can do what

An agent can create a secret with no URLs. So an agent cannot create an api_key secret.

CLI

A --field value has the form label=type=value. A --grant value has the form <agt_…|@handle>=<VARIABLE_NAME>. It gives that agent view access and names the variable its runs read.
There is no CLI verb for update or delete. Use the API or the Keychain page.

API

The create body takes name, template, fields, and optional description, urls, visibility and initialGrants. Each initial grant names a principal, a permission (view, edit or admin) and an envVarName. The list cursor is the nextCursor of the previous page. List drops secrets you cannot see after it reads a page. So a page can hold fewer items than limit, and totalCount counts only this page.

Errors

A secret you cannot see returns 404 resource_not_found, not 403. For shared codes, see API conventions.

Limits

  • Name: 1 to 80 characters.
  • Description: 500 characters.
  • Field label: 100 characters.
  • Reveal reason: 200 characters.
  • List search q: 100 characters.
  • List page: 50 by default, 100 at most.
  • Grants inlined on get: 25.
  • Initial grant variable name: 64 characters, matching [A-Z_][A-Z0-9_]*.

Secrets

Why only a person can reveal a value, and how runs use a secret.

Add an MCP server

Point an MCP server at a secret by name.

Connection

OAuth and API key connections to outside services.

Environment and device

Where a run executes and what reaches it.