Skip to content
Esc
↑↓navigate↵open⌘Jpreview

Open an encrypted .env file

Decrypts the values of an encrypted .env file on the server, with the key the file names, and returns them. Authorized exactly like resolving the environment for injection, refused as a whole if any value was altered, and recorded in the audit trail with the variable names. When the file was encrypted with a key that has since been rotated, the answer also carries the active key to re-encrypt it with.

POST/environments/{envId}/sealed-values/open
Path parameters
envIdstring<uuid>required
matches ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
Request body
requiredapplication/json
keyIdstringrequired
matches ^ek_[0-9a-f]{8}$
entriesobjectrequired
Responses
200Success.
keyIdstringrequired
valuesobjectrequired
activeKeySealingKey
Show properties
keyIdstringrequired
publicKeystringrequired
400The request failed validation. `field` names the offending input.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
401No credential was presented, or it is invalid or revoked.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
403The credential is valid but lacks the required scope, role or team access.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
Request
curl -X POST "https://api.varsafe.dev/environments/%3Cuuid%3E/sealed-values/open" \
  -H "Content-Type: application/json" \
  -d '{
  "keyId": "string",
  "entries": {}
}'
Response
{
  "keyId": "string",
  "values": {},
  "activeKey": {
    "keyId": "string",
    "publicKey": "string"
  }
}