Files
coder/docs/reference/api/secrets.md
T
dylanhuff-at-coder d5a3963167 feat: add bulk user secret import endpoint and SDK client (PLAT-240) (#26724)
Adds `POST /api/v2/users/{user}/secrets/batch` and
`codersdk.Client.ImportUserSecrets` to import env, JSON, or YAML secrets
atomically. The endpoint validates each entry, rolls back the full batch
on conflicts or limits, omits secret values from responses and audit
logs, and imports keys that cannot be injected as environment variables
with an empty `env_name`.

Part of the [PLAT-240 bulk secret import
stack](https://linear.app/codercom/issue/PLAT-240). Reviewed and updated
by Coder Agents on behalf of @dylanhuff-at-coder.
2026-07-23 14:55:34 -07:00

11 KiB
Generated

Secrets

List user secrets

Code samples

# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

GET /api/v2/users/{user}/secrets

Parameters

Name In Type Required Description
user path string true User ID, username, or me

Example responses

200 Response

[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]

Responses

Status Meaning Description Schema
200 OK OK array of codersdk.UserSecret

Response Schema

Status Code 200

Name Type Required Restrictions Description
[array item] array false
» created_at string(date-time) false
» description string false
» env_name string false
» file_path string false
» id string(uuid) false
» name string false
» updated_at string(date-time) false

To perform this operation, you must be authenticated. Learn more.

Create a new user secret

Code samples

# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

POST /api/v2/users/{user}/secrets

Body parameter

{
  "description": "string",
  "env_name": "string",
  "file_path": "string",
  "name": "string",
  "value": "string"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
body body codersdk.CreateUserSecretRequest true Create secret request

Example responses

201 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
201 Created Created codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.

Import user secrets from a file

Code samples

# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets/batch \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

POST /api/v2/users/{user}/secrets/batch

Body parameter

{
  "content": "string",
  "format": "env"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
body body codersdk.ImportUserSecretsRequest true Import secrets request

Example responses

201 Response

[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]

Responses

Status Meaning Description Schema
201 Created Created array of codersdk.UserSecret
400 Bad Request Bad Request codersdk.Response
409 Conflict Conflict codersdk.Response
413 Payload Too Large Request Entity Too Large codersdk.Response

Response Schema

Status Code 201

Name Type Required Restrictions Description
[array item] array false
» created_at string(date-time) false
» description string false
» env_name string false
» file_path string false
» id string(uuid) false
» name string false
» updated_at string(date-time) false

To perform this operation, you must be authenticated. Learn more.

Get a user secret by name

Code samples

# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

GET /api/v2/users/{user}/secrets/{name}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name

Example responses

200 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
200 OK OK codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.

Delete a user secret

Code samples

# Example request using curl
curl -X DELETE http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Coder-Session-Token: API_KEY'

DELETE /api/v2/users/{user}/secrets/{name}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name

Responses

Status Meaning Description Schema
204 No Content No Content

To perform this operation, you must be authenticated. Learn more.

Update a user secret

Code samples

# Example request using curl
curl -X PATCH http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

PATCH /api/v2/users/{user}/secrets/{name}

Body parameter

{
  "description": "string",
  "env_name": "string",
  "file_path": "string",
  "value": "string"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name
body body codersdk.UpdateUserSecretRequest true Update secret request

Example responses

200 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
200 OK OK codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.