Skip to content
varsafe
Esc
↑↓navigate↵open⌘Jpreview

List secrets

Lists secret keys and metadata for a project environment. Values are never included — that requires secrets:read_values.

GET/secrets
Query parameters
projectIdstring<uuid>required
matches ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
environmentstringrequired
min length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
pageinteger
min 1 · max 10000
pageSizeinteger
max 500
representationstring
Allowed:materializedsource
Responses
200Success.
Any of:
SecretRef[]
Array of SecretRef
idstring<uuid>required
projectIdstring<uuid>required
environmentstringrequired
min length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
keystringrequired
min length 1 · max length 255
versionintegerrequired
max 9007199254740991
createdAtstring<date-time>required
updatedAtstring<date-time>required
object
dataSecretRef[]required
Show properties
Array of SecretRef
idstring<uuid>required
projectIdstring<uuid>required
environmentstringrequired
min length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
keystringrequired
min length 1 · max length 255
versionintegerrequired
max 9007199254740991
createdAtstring<date-time>required
updatedAtstring<date-time>required
totalintegerrequired
min 0 · max 9007199254740991
pageintegerrequired
max 9007199254740991
pageSizeintegerrequired
max 9007199254740991
400The request failed validation. `field` names the offending input.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
401No credential was presented, or it is invalid or revoked.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
403The credential is valid but lacks the required scope, role or team access.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
Request
curl -X GET "https://api.varsafe.dev/secrets?projectId=%3Cuuid%3E&environment=string"
Response
[
  {
    "id": "<uuid>",
    "projectId": "<uuid>",
    "environment": "string",
    "key": "string",
    "version": 0,
    "createdAt": "2024-01-01T00:00:00Z",
    "updatedAt": "2024-01-01T00:00:00Z"
  }
]