# Update secrets (https://developer.godaddy.com/en/docs/references/rest/hosting/update-secrets)

---
title: Update secrets
description: 'Partial update via [JSON Patch (RFC 6902)](https://datatracker.'
full: true
---

Full description

> Partial update via [JSON Patch (RFC 6902)](https://datatracker.ietf.org/doc/html/rfc6902). The request body is an array of operations applied in order and atomically. At least one operation must be present. The combined total number of operations must not exceed 50. Existing secrets not referenced in the request are left unchanged.   The `variant` query parameter selects the environment (`PREVIEW` or `PUBLISH`). Defaults to `PREVIEW`.   Supported operations are `add`, `replace`, and `remove`. Any other op returns `400 Bad Request`. Each path is `/&#123;name&#125;` — a JSON Pointer to the secret name, not an index into the `ScopedSecretSet` response.  Encode `/` in a secret name as `~1` per RFC 6901. Secret names must start with a letter and contain only letters, digits, `/`, `_`, `+`, `=`, `.`, `@`, or `-`. Reserved environment variable names are rejected. System-managed and reserved secrets cannot be updated or deleted.   For `add` and `replace`, `value` is the secret string (max 8 KB). `remove` does not take a value. A request that would leave the application with more than 50 secrets returns `400 Bad Request`.   The response is secret metadata after the update. Values are never included.

## PATCH /apps/{appId}/secrets

Update secrets

Partial update via [JSON Patch (RFC 6902)](https://datatracker.ietf.org/doc/html/rfc6902). The request body is an array of operations applied in order and atomically. At least one operation must be present. The combined total number of operations must not exceed 50. Existing secrets not referenced in the request are left unchanged.

The `variant` query parameter selects the environment (`PREVIEW` or `PUBLISH`). Defaults to `PREVIEW`.

Supported operations are `add`, `replace`, and `remove`. Any other op returns `400 Bad Request`. Each path is `/{name}` — a JSON Pointer to the secret name, not an index into the `ScopedSecretSet` response.
Encode `/` in a secret name as `~1` per RFC 6901. Secret names must start with a letter and contain only letters, digits, `/`, `_`, `+`, `=`, `.`, `@`, or `-`. Reserved environment variable names are rejected. System-managed and reserved secrets cannot be updated or deleted.

For `add` and `replace`, `value` is the secret string (max 8 KB). `remove` does not take a value. A request that would leave the application with more than 50 secrets returns `400 Bad Request`.

The response is secret metadata after the update. Values are never included.


### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `variant` | unknown | no | The environment variant to target. Defaults to `PREVIEW`. |

### Header parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `Idempotency-Key` | string <uuid> | no | Client-generated UUID that makes a request safe to retry. Supplying the same key on a retry with an identical request body returns the original response without triggering a second operation. Retrying with the same key while the first request is still in flight returns `409 Conflict`. Reusing a key with a different request body returns `422 Unprocessable Entity` with `details[].issue` `IDEMPOTENCY_KEY_MISMATCH`. Keys are retained for 24 hours after the operation completes, after which the key may be reused. |

### Request body (required)

Content-Type: `application/json-patch+json`

Schema:

- schema reference: `#/x-ext/785f9fe`

### Responses

**200** — Secret metadata after the update. Values are never included.

Content-Type: `application/json`

Schema:

- schema reference: `#/x-ext/3c029b5`

**400** — The request body or parameters did not pass schema validation.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**401** — Authentication credentials are missing or invalid.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — The caller is authenticated, but the request is not permitted: either the access token does not carry the scope this operation requires, or the operation is disabled for this account.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — The requested resource does not exist.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**409** — The request conflicts with the current state of the resource.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — The request was well-formed but could not be processed due to a business rule violation.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Rate limit exceeded. A `429` response may come in one of two shapes: an empty body with `RateLimit-Limit`, `RateLimit-Remaining`, and `RateLimit-Reset` headers; or a JSON `Error` body with `Retry-After` and `RateLimit-*` headers. Clients should honour whichever headers are present and should not assume a JSON body is available on every `429`.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**501** — The request is contract-valid, but the operation, or a value the request names, is not applicable to this deployment. `details[].issue` is always `NOT_APPLICABLE`. For example, deployments and restarts are offered for `NODEJS` applications only, and a hosting product this deployment does not serve is answered here rather than with a `400`.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**503** — The service is temporarily unable to handle the request. Retry after a short delay. May include a `Retry-After` header hinting at when to retry.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**Security:** requires `bearerAuth`.
