Support

How to manage secrets

View as Markdown

Add, update, and delete per-variant environment secrets for a hosting app.

Overview

This page covers managing environment secrets for a hosted app. You configure secrets per variant (PREVIEW or PUBLISH). A single call can add, update, or delete them. The API never returns secret values.

Go to Deploy your Node.js app if you haven't created and deployed an app yet. Go to Hosting concepts for background on the variant model.

Prerequisites

The following prerequisites are required before you can manage secrets for your app:

  • a Personal Access Token with the hosting.secret:read scope (list operations) or hosting.secret:write scope (write operations)

List secrets

GET /apps/{appId}/secrets returns a deduplicated flat list of secret metadata for the app. Values are never included.

The following procedure lists secrets for an app.

  • List secrets:

    curl -s "$BASE_URL/v1/hosting/apps/$APP_ID/secrets?variant=PREVIEW" \
      -H "Authorization: Bearer $GODADDY_PAT" | jq .

The response includes secret names and last-updated timestamps. Values are omitted.

Add, update, or delete secrets

PATCH /apps/{appId}/secrets applies a JSON Patch (RFC 6902) array atomically. Pass the environment as the variant query parameter (PREVIEW or PUBLISH). Each call accepts up to 50 operations total. Supported ops are add, replace, and remove. Each path is /{name}.

The following procedure adds a new preview secret, updates an existing preview secret, and deletes another preview secret in one call.

  • Submit the patch:

    curl -s -X PATCH "$BASE_URL/v1/hosting/apps/$APP_ID/secrets?variant=PREVIEW" \
      -H "Authorization: Bearer $GODADDY_PAT" \
      -H "Content-Type: application/json-patch+json" \
      -d '[
        { "op": "add",     "path": "/STRIPE_KEY", "value": "sk_test_abc123" },
        { "op": "replace", "path": "/DB_URL",     "value": "postgres://host/newdb" },
        { "op": "remove",  "path": "/OLD_FLAG" }
      ]' | jq .

The response is secret metadata. Values are never included.

Common errors

The following table lists common errors and recommended actions:

StatusCauseAction
401Expired or revoked PAT, or missing scopeConfirm the token includes hosting.secret:read for list or hosting.secret:write for patch
404App id not foundConfirm the id from GET /apps
409Secret already exists (on add)Use replace instead of add for existing secrets
422Validation errorCheck the patch array structure, op values (add/replace/remove), and path format
429Rate limit exceededBack off and retry. Go to Rate limits for handling guidance

Agent & Automation Notes

Scopeshosting.secret:read, hosting.secret:write
Rate limit60 req/min per credential
IdempotentNo
DestructiveYes — confirm before executing
On failureThe secrets write endpoint is not idempotent. Duplicate additions return an error. Deletions are irreversible — confirm secret names before submitting.

Last updated on

How is this guide?

On this page