Secrets
Secret management endpoints
List secrets with components
Required Permissions:
secrets:read
Lists all secrets for the specified organization, each with the inputs, outputs, enrichments and transforms that reference it. A secret with no references in any of those lists can be deleted; one with references cannot (see DELETE). Pipeline-node config overrides are not included in these lists but do block deletion.
path Parameters
organization_idOrganization ID
query Parameters
limitLimit number of results
offsetOffset results
List secrets with components › Responses
Create secret
Required Permissions:
secrets:write
Creates a new secret for the specified organization
path Parameters
organization_idOrganization ID
Create secret › Request Body
Decision Table
| Variant | Matching Criteria |
|---|---|
| type = object | |
| type = object |
Create secret › Responses
Created
created_atdescriptionidnameorganization_idShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atGet secret with components
Required Permissions:
secrets:read
Gets a specific secret by ID with the inputs, outputs, enrichments and transforms that reference it. Use this as the pre-check before DELETE: references in any of those lists mean the secret cannot be deleted. Pipeline-node config overrides are not included here but do block deletion, so an empty result is not a guarantee the delete will succeed.
path Parameters
organization_idOrganization ID
secret_idSecret ID
Get secret with components › Responses
OK
created_atdescriptionidnameorganization_idShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atDelete secret
Required Permissions:
secrets:delete
Deletes a specific secret by ID. A secret that is still referenced cannot be deleted: the request is refused with 409 and the error message names what holds the reference. "Referenced" means configured on an input, output, enrichment or transform, or on a pipeline node's config override — it does not require the pipeline to be running, so an idle component still blocks the delete. Use GET /v2/{organization_id}/secrets/{secret_id} to see the referencing inputs, outputs, enrichments and transforms before deleting; note that response does not list pipeline-node overrides, so a 409 can name a pipeline the pre-check did not show. Secrets shared with other organizations must have their shares removed first.
path Parameters
organization_idOrganization ID
secret_idSecret ID
Delete secret › Responses
No Content
Update secret
Required Permissions:
secrets:write
Updates a specific secret by ID
path Parameters
organization_idOrganization ID
secret_idSecret ID
Update secret › Request Body
Decision Table
| Variant | Matching Criteria |
|---|---|
| type = object | |
| type = object |
Update secret › Responses
OK
created_atdescriptionidnameorganization_idShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_at