sec_ plus 16 letters and digits. The dashboard lists secrets on the Keychain page in settings. For how runs use a secret, see Secrets.
A secret has no lifecycle states. It exists until its owner or a workspace admin deletes it.
Fields
List returns the base fields. Get, create, update, replace and transfer return the base fields plus the detail fields. No response except a reveal carries a value.string
required
Always
secret.string
required
The secret id,
sec_….string
required
Unique in the workspace. 1 to 80 characters.
string
required
The type:
api_key, login, identity or custom.string
Up to 500 characters. Null when not set.
string[]
required
The HTTPS hosts the secret is meant for. Each URL names one exact host, with no wildcard. Can be empty, except for
api_key.string
Eight asterisks plus the last 4 characters of the first
password field, or of the first field. Null when that value is shorter than 4 characters.object[]
required
One entry per field, with labels and types only.
object
required
Who created the secret:
type (user or agent), id and label.object
The owning person:
id and name. Null when an agent created the secret.string
required
private, company or custom. Defaults to company.integer
required
How many grants name this secret.
string
When a person last revealed the value. Null until the first reveal.
string
required
ISO 8601 timestamp.
string
required
ISO 8601 timestamp.
object[]
Detail only. Like
fieldSummary, plus required.string
Detail only. When the fields were last replaced. Null until the first replace.
string
Detail only. When the value was last revealed. Null until the first reveal.
object
Only on get with
expand[]=grants. A list of up to 25 grants, newest first, with hasMore and totalCount.string
required
Always
secret_value.string
required
The secret id,
sec_….object[]
required
One entry per field:
label, type and the decrypted value.string
required
When the reveal happened.
Who can do what
An agent can create a secret with no URLs. So an agent cannot create an
api_key secret.
CLI
A
--field value has the form label=type=value. A --grant value has the form <agt_…|@handle>=<VARIABLE_NAME>. It gives that agent view access and names the variable its runs read.
API
The create body takes
name, template, fields, and optional description, urls, visibility and initialGrants. Each initial grant names a principal, a permission (view, edit or admin) and an envVarName.
The list cursor is the nextCursor of the previous page. List drops secrets you cannot see after it reads a page. So a page can hold fewer items than limit, and totalCount counts only this page.
Errors
A secret you cannot see returns 404
resource_not_found, not 403. For shared codes, see API conventions.
Limits
- Name: 1 to 80 characters.
- Description: 500 characters.
- Field label: 100 characters.
- Reveal reason: 200 characters.
- List search
q: 100 characters. - List page: 50 by default, 100 at most.
- Grants inlined on get: 25.
- Initial grant variable name: 64 characters, matching
[A-Z_][A-Z0-9_]*.
Secrets
Why only a person can reveal a value, and how runs use a secret.
Add an MCP server
Point an MCP server at a secret by name.
Connection
OAuth and API key connections to outside services.
Environment and device
Where a run executes and what reaches it.