Support

Update secrets

View as Markdown

Partial update via [JSON Patch (RFC 6902)](https://datatracker.

Full description

Partial update via JSON Patch (RFC 6902). The request body is an array of operations applied in order and atomically. At least one operation must be present. The combined total number of operations must not exceed 50. Existing secrets not referenced in the request are left unchanged. The variant query parameter selects the environment (PREVIEW or PUBLISH). Defaults to PREVIEW. Supported operations are add, replace, and remove. Any other op returns 400 Bad Request. Each path is /{name} — a JSON Pointer to the secret name, not an index into the ScopedSecretSet response. Encode / in a secret name as ~1 per RFC 6901. Secret names must start with a letter and contain only letters, digits, /, _, +, =, ., @, or -. Reserved environment variable names are rejected. System-managed and reserved secrets cannot be updated or deleted. For add and replace, value is the secret string (max 8 KB). remove does not take a value. A request that would leave the application with more than 50 secrets returns 400 Bad Request. The response is secret metadata after the update. Values are never included.

PATCH
/apps/{appId}/secrets

Authorization

bearerAuth
AuthorizationBearer <token>

Personal Access Token (PAT). Generate one from the developer dashboard. Pass as: Authorization: Bearer <token>.

In: header

Path Parameters

appId*string

Application identifier in {PRODUCT}-{id} form. The prefix is the application type in upper case — an upper-case letter followed by any number of upper-case letters, digits, or underscores — then a hyphen, then the identifier. For NODEJS, the suffix is a 10-character nanoid. Example: NODEJS-aBcDeFgHiJ.

Match^[A-Z][A-Z0-9_]*-[A-Za-z0-9_-]+$

Query Parameters

variant?Environment

The environment variant to target. Defaults to PREVIEW.

Header Parameters

Idempotency-Key?string

Client-generated UUID that makes a request safe to retry. Supplying the same key on a retry with an identical request body returns the original response without triggering a second operation. Retrying with the same key while the first request is still in flight returns 409 Conflict. Reusing a key with a different request body returns 422 Unprocessable Entity with details[].issue IDEMPOTENCY_KEY_MISMATCH. Keys are retained for 24 hours after the operation completes, after which the key may be reused.

Formatuuid
traceparent?string

W3C Trace Context identifier for this request. Clients should send a traceparent on every request so the trace can be correlated across services. See https://www.w3.org/TR/trace-context/ for the format.

Match^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Request Body

application/json-patch+json

An array of JSON patch objects to apply partial updates to resources.

[index: integer]?

The JSON patch object to apply partial updates to resources.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://example.com/apps/string/secrets" \  -H "Content-Type: application/json-patch+json" \  -d '<0>    <op>add</op>  </0>'
{  "shared": {    "secrets": [      {        "name": "string",        "systemManaged": true,        "createdAt": "stringstringstringst",        "updatedAt": "stringstringstringst"      }    ]  },  "variants": {    "preview": {      "secrets": [        {          "name": "string",          "systemManaged": true,          "createdAt": "stringstringstringst",          "updatedAt": "stringstringstringst"        }      ]    },    "publish": {      "secrets": [        {          "name": "string",          "systemManaged": true,          "createdAt": "stringstringstringst",          "updatedAt": "stringstringstringst"        }      ]    }  }}

Agent & Automation Notes

Scopeshosting.application:read, hosting.application:create, hosting.application:update, hosting.application:delete, hosting.source:write, hosting.deployment:execute, hosting.secret:write, hosting.log:read
Rate limit10–120 req/min per client IP depending on operation
On failureCreate app returns 202 with a job. Poll GET /app-operations/{operationId} until app is ready. Upload source and deployments return 202 with an operation ID. Poll the matching status endpoint until complete. GET operations are safe to retry. Do not resubmit writes without checking current state.

Last updated on

How is this guide?