Files
coder/docs/reference/api/secrets.md
T
Zach 85984ff142 feat: add enable/disable support for user secrets (#27537)
Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
2026-07-28 09:58:33 -06:00

16 KiB
Generated

Secrets

List user secrets

Code samples

# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

GET /api/v2/users/{user}/secrets

Parameters

Name In Type Required Description
user path string true User ID, username, or me

Example responses

200 Response

[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "enabled": true,
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]

Responses

Status Meaning Description Schema
200 OK OK array of codersdk.UserSecret

Response Schema

Status Code 200

Name Type Required Restrictions Description
[array item] array false
» created_at string(date-time) false
» description string false
» enabled boolean false Enabled controls whether the secret is injected into workspaces. Disabled secrets remain visible and editable, but are not added to the agent manifest, so they are not exposed as environment variables or written to secret files.
» env_name string false
» file_path string false
» id string(uuid) false
» name string false
» updated_at string(date-time) false

To perform this operation, you must be authenticated. Learn more.

Create a new user secret

Code samples

# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

POST /api/v2/users/{user}/secrets

Body parameter

{
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "name": "string",
  "value": "string"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
body body codersdk.CreateUserSecretRequest true Create secret request

Example responses

201 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
201 Created Created codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.

Import user secrets from a file

Code samples

# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets/batch \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

POST /api/v2/users/{user}/secrets/batch

Body parameter

{
  "content": "string",
  "format": "env"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
body body codersdk.ImportUserSecretsRequest true Import secrets request

Example responses

201 Response

[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "enabled": true,
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]

Responses

Status Meaning Description Schema
201 Created Created array of codersdk.UserSecret
400 Bad Request Bad Request codersdk.Response
409 Conflict Conflict codersdk.Response
413 Payload Too Large Request Entity Too Large codersdk.Response

Response Schema

Status Code 201

Name Type Required Restrictions Description
[array item] array false
» created_at string(date-time) false
» description string false
» enabled boolean false Enabled controls whether the secret is injected into workspaces. Disabled secrets remain visible and editable, but are not added to the agent manifest, so they are not exposed as environment variables or written to secret files.
» env_name string false
» file_path string false
» id string(uuid) false
» name string false
» updated_at string(date-time) false

To perform this operation, you must be authenticated. Learn more.

Get a user secret by name

Code samples

# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

GET /api/v2/users/{user}/secrets/{name}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name

Example responses

200 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
200 OK OK codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.

Delete a user secret

Code samples

# Example request using curl
curl -X DELETE http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Coder-Session-Token: API_KEY'

DELETE /api/v2/users/{user}/secrets/{name}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name

Responses

Status Meaning Description Schema
204 No Content No Content

To perform this operation, you must be authenticated. Learn more.

Update a user secret

Code samples

# Example request using curl
curl -X PATCH http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'

PATCH /api/v2/users/{user}/secrets/{name}

Body parameter

{
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "value": "string"
}

Parameters

Name In Type Required Description
user path string true User ID, username, or me
name path string true Secret name
body body codersdk.UpdateUserSecretRequest true Update secret request

Example responses

200 Response

{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}

Responses

Status Meaning Description Schema
200 OK OK codersdk.UserSecret

To perform this operation, you must be authenticated. Learn more.