How to manage secrets
View as MarkdownAdd, update, and delete per-variant environment secrets for a hosting app.
Overview
This page covers managing environment secrets for a hosted app. You configure secrets per variant (PREVIEW or PUBLISH). A single call can add, update, or delete them. The API never returns secret values.
Go to Deploy your Node.js app if you haven't created and deployed an app yet. Go to Hosting concepts for background on the variant model.
Prerequisites
The following prerequisites are required before you can manage secrets for your app:
- a Personal Access Token with the
hosting.secret:readscope (list operations) orhosting.secret:writescope (write operations)
List secrets
GET /apps/{appId}/secrets returns a deduplicated flat list of secret metadata for the app. Values are never included.
The following procedure lists secrets for an app.
-
List secrets:
curl -s "$BASE_URL/v1/hosting/apps/$APP_ID/secrets?variant=PREVIEW" \ -H "Authorization: Bearer $GODADDY_PAT" | jq .
The response includes secret names and last-updated timestamps. Values are omitted.
Add, update, or delete secrets
PATCH /apps/{appId}/secrets applies a JSON Patch (RFC 6902) array atomically. Pass the environment as the variant query parameter (PREVIEW or PUBLISH). Each call accepts up to 50 operations total. Supported ops are add, replace, and remove. Each path is /{name}.
The following procedure adds a new preview secret, updates an existing preview secret, and deletes another preview secret in one call.
-
Submit the patch:
curl -s -X PATCH "$BASE_URL/v1/hosting/apps/$APP_ID/secrets?variant=PREVIEW" \ -H "Authorization: Bearer $GODADDY_PAT" \ -H "Content-Type: application/json-patch+json" \ -d '[ { "op": "add", "path": "/STRIPE_KEY", "value": "sk_test_abc123" }, { "op": "replace", "path": "/DB_URL", "value": "postgres://host/newdb" }, { "op": "remove", "path": "/OLD_FLAG" } ]' | jq .
The response is secret metadata. Values are never included.
Common errors
The following table lists common errors and recommended actions:
| Status | Cause | Action |
|---|---|---|
401 | Expired or revoked PAT, or missing scope | Confirm the token includes hosting.secret:read for list or hosting.secret:write for patch |
404 | App id not found | Confirm the id from GET /apps |
409 | Secret already exists (on add) | Use replace instead of add for existing secrets |
422 | Validation error | Check the patch array structure, op values (add/replace/remove), and path format |
429 | Rate limit exceeded | Back off and retry. Go to Rate limits for handling guidance |
Agent & Automation Notes
hosting.secret:read, hosting.secret:writeRelated
API References
Guides
Concepts
Tutorials
Last updated on
How is this guide?