List secrets
Lists secret keys and metadata for a project environment. Values are never included — that requires secrets:read_values.
GET
/secretsQuery parameters
projectIdstring<uuid>requiredmatches ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
environmentstringrequiredmin length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
pageintegermin 1 · max 10000
pageSizeintegermax 500
representationstringAllowed:
materializedsourceResponses
200Success.
Any of:
SecretRef[]
Array of
SecretRefidstring<uuid>requiredprojectIdstring<uuid>requiredenvironmentstringrequiredmin length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
keystringrequiredmin length 1 · max length 255
versionintegerrequiredmax 9007199254740991
createdAtstring<date-time>requiredupdatedAtstring<date-time>requiredobject
dataSecretRef[]requiredShow propertiesHide properties
Array of
SecretRefidstring<uuid>requiredprojectIdstring<uuid>requiredenvironmentstringrequiredmin length 1 · max length 50 · matches ^[a-z0-9][a-z0-9-]*$
keystringrequiredmin length 1 · max length 255
versionintegerrequiredmax 9007199254740991
createdAtstring<date-time>requiredupdatedAtstring<date-time>requiredtotalintegerrequiredmin 0 · max 9007199254740991
pageintegerrequiredmax 9007199254740991
pageSizeintegerrequiredmax 9007199254740991
400The request failed validation. `field` names the offending input.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
401No credential was presented, or it is invalid or revoked.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
403The credential is valid but lacks the required scope, role or team access.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
Request
curl -X GET "https://api.varsafe.dev/secrets?projectId=%3Cuuid%3E&environment=string"const response = await fetch("https://api.varsafe.dev/secrets?projectId=%3Cuuid%3E&environment=string", {
method: "GET"
});import requests
response = requests.get(
"https://api.varsafe.dev/secrets?projectId=%3Cuuid%3E&environment=string",
)Response
[
{
"id": "<uuid>",
"projectId": "<uuid>",
"environment": "string",
"key": "string",
"version": 0,
"createdAt": "2024-01-01T00:00:00Z",
"updatedAt": "2024-01-01T00:00:00Z"
}
]{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}