# Secrets

## List user secrets [#list-user-secrets]

### Code samples [#code-samples]

```sh
# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'
```

`GET /api/v2/users/{user}/secrets`

### Parameters [#parameters]

| Name   | In   | Type   | Required | Description              |
| ------ | ---- | ------ | -------- | ------------------------ |
| `user` | path | string | true     | User ID, username, or me |

### Example responses [#example-responses]

> 200 Response

```json
[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "enabled": true,
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]
```

### Responses [#responses]

| Status | Meaning                                                 | Description | Schema                                                                               |
| ------ | ------------------------------------------------------- | ----------- | ------------------------------------------------------------------------------------ |
| 200    | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK          | array of [codersdk.UserSecret](/beta-docs/reference/api/schemas/#codersdkusersecret) |

<h3 id="list-user-secrets-responseschema">Response Schema</h3>

Status Code **200**

| Name            | Type              | Required | Restrictions | Description                                                                                                                                                                                                                          |
| --------------- | ----------------- | -------- | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `[array item]`  | array             | false    |              |                                                                                                                                                                                                                                      |
| `» created_at`  | string(date-time) | false    |              |                                                                                                                                                                                                                                      |
| `» description` | string            | false    |              |                                                                                                                                                                                                                                      |
| `» enabled`     | boolean           | false    |              | Enabled controls whether the secret is injected into workspaces. Disabled secrets remain visible and editable, but are not added to the agent manifest, so they are not exposed as environment variables or written to secret files. |
| `» env_name`    | string            | false    |              |                                                                                                                                                                                                                                      |
| `» file_path`   | string            | false    |              |                                                                                                                                                                                                                                      |
| `» id`          | string(uuid)      | false    |              |                                                                                                                                                                                                                                      |
| `» name`        | string            | false    |              |                                                                                                                                                                                                                                      |
| `» updated_at`  | string(date-time) | false    |              |                                                                                                                                                                                                                                      |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).

## Create a new user secret [#create-a-new-user-secret]

### Code samples [#code-samples-1]

```sh
# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'
```

`POST /api/v2/users/{user}/secrets`

> Body parameter

```json
{
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "name": "string",
  "value": "string"
}
```

### Parameters [#parameters-1]

| Name   | In   | Type                                                                                                  | Required | Description              |
| ------ | ---- | ----------------------------------------------------------------------------------------------------- | -------- | ------------------------ |
| `user` | path | string                                                                                                | true     | User ID, username, or me |
| `body` | body | [codersdk.CreateUserSecretRequest](/beta-docs/reference/api/schemas/#codersdkcreateusersecretrequest) | true     | Create secret request    |

### Example responses [#example-responses-1]

> 201 Response

```json
{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}
```

### Responses [#responses-1]

| Status | Meaning                                                      | Description | Schema                                                                      |
| ------ | ------------------------------------------------------------ | ----------- | --------------------------------------------------------------------------- |
| 201    | [Created](https://tools.ietf.org/html/rfc7231#section-6.3.2) | Created     | [codersdk.UserSecret](/beta-docs/reference/api/schemas/#codersdkusersecret) |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).

## Import user secrets from a file [#import-user-secrets-from-a-file]

### Code samples [#code-samples-2]

```sh
# Example request using curl
curl -X POST http://coder-server:8080/api/v2/users/{user}/secrets/batch \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'
```

`POST /api/v2/users/{user}/secrets/batch`

> Body parameter

```json
{
  "content": "string",
  "format": "env"
}
```

### Parameters [#parameters-2]

| Name   | In   | Type                                                                                                    | Required | Description              |
| ------ | ---- | ------------------------------------------------------------------------------------------------------- | -------- | ------------------------ |
| `user` | path | string                                                                                                  | true     | User ID, username, or me |
| `body` | body | [codersdk.ImportUserSecretsRequest](/beta-docs/reference/api/schemas/#codersdkimportusersecretsrequest) | true     | Import secrets request   |

### Example responses [#example-responses-2]

> 201 Response

```json
[
  {
    "created_at": "2019-08-24T14:15:22Z",
    "description": "string",
    "enabled": true,
    "env_name": "string",
    "file_path": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "name": "string",
    "updated_at": "2019-08-24T14:15:22Z"
  }
]
```

### Responses [#responses-2]

| Status | Meaning                                                                 | Description                | Schema                                                                               |
| ------ | ----------------------------------------------------------------------- | -------------------------- | ------------------------------------------------------------------------------------ |
| 201    | [Created](https://tools.ietf.org/html/rfc7231#section-6.3.2)            | Created                    | array of [codersdk.UserSecret](/beta-docs/reference/api/schemas/#codersdkusersecret) |
| 400    | [Bad Request](https://tools.ietf.org/html/rfc7231#section-6.5.1)        | Bad Request                | [codersdk.Response](/beta-docs/reference/api/schemas/#codersdkresponse)              |
| 409    | [Conflict](https://tools.ietf.org/html/rfc7231#section-6.5.8)           | Conflict                   | [codersdk.Response](/beta-docs/reference/api/schemas/#codersdkresponse)              |
| 413    | [Payload Too Large](https://tools.ietf.org/html/rfc7231#section-6.5.11) | Request body exceeds 8 MiB | [codersdk.Response](/beta-docs/reference/api/schemas/#codersdkresponse)              |

<h3 id="import-user-secrets-from-a-file-responseschema">Response Schema</h3>

Status Code **201**

| Name            | Type              | Required | Restrictions | Description                                                                                                                                                                                                                          |
| --------------- | ----------------- | -------- | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `[array item]`  | array             | false    |              |                                                                                                                                                                                                                                      |
| `» created_at`  | string(date-time) | false    |              |                                                                                                                                                                                                                                      |
| `» description` | string            | false    |              |                                                                                                                                                                                                                                      |
| `» enabled`     | boolean           | false    |              | Enabled controls whether the secret is injected into workspaces. Disabled secrets remain visible and editable, but are not added to the agent manifest, so they are not exposed as environment variables or written to secret files. |
| `» env_name`    | string            | false    |              |                                                                                                                                                                                                                                      |
| `» file_path`   | string            | false    |              |                                                                                                                                                                                                                                      |
| `» id`          | string(uuid)      | false    |              |                                                                                                                                                                                                                                      |
| `» name`        | string            | false    |              |                                                                                                                                                                                                                                      |
| `» updated_at`  | string(date-time) | false    |              |                                                                                                                                                                                                                                      |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).

## Get a user secret by name [#get-a-user-secret-by-name]

### Code samples [#code-samples-3]

```sh
# Example request using curl
curl -X GET http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'
```

`GET /api/v2/users/{user}/secrets/{name}`

### Parameters [#parameters-3]

| Name   | In   | Type   | Required | Description              |
| ------ | ---- | ------ | -------- | ------------------------ |
| `user` | path | string | true     | User ID, username, or me |
| `name` | path | string | true     | Secret name              |

### Example responses [#example-responses-3]

> 200 Response

```json
{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}
```

### Responses [#responses-3]

| Status | Meaning                                                 | Description | Schema                                                                      |
| ------ | ------------------------------------------------------- | ----------- | --------------------------------------------------------------------------- |
| 200    | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK          | [codersdk.UserSecret](/beta-docs/reference/api/schemas/#codersdkusersecret) |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).

## Delete a user secret [#delete-a-user-secret]

### Code samples [#code-samples-4]

```sh
# Example request using curl
curl -X DELETE http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Coder-Session-Token: API_KEY'
```

`DELETE /api/v2/users/{user}/secrets/{name}`

### Parameters [#parameters-4]

| Name   | In   | Type   | Required | Description              |
| ------ | ---- | ------ | -------- | ------------------------ |
| `user` | path | string | true     | User ID, username, or me |
| `name` | path | string | true     | Secret name              |

### Responses [#responses-4]

| Status | Meaning                                                         | Description | Schema |
| ------ | --------------------------------------------------------------- | ----------- | ------ |
| 204    | [No Content](https://tools.ietf.org/html/rfc7231#section-6.3.5) | No Content  |        |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).

## Update a user secret [#update-a-user-secret]

### Code samples [#code-samples-5]

```sh
# Example request using curl
curl -X PATCH http://coder-server:8080/api/v2/users/{user}/secrets/{name} \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json' \
  -H 'Coder-Session-Token: API_KEY'
```

`PATCH /api/v2/users/{user}/secrets/{name}`

> Body parameter

```json
{
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "value": "string"
}
```

### Parameters [#parameters-5]

| Name   | In   | Type                                                                                                  | Required | Description              |
| ------ | ---- | ----------------------------------------------------------------------------------------------------- | -------- | ------------------------ |
| `user` | path | string                                                                                                | true     | User ID, username, or me |
| `name` | path | string                                                                                                | true     | Secret name              |
| `body` | body | [codersdk.UpdateUserSecretRequest](/beta-docs/reference/api/schemas/#codersdkupdateusersecretrequest) | true     | Update secret request    |

### Example responses [#example-responses-4]

> 200 Response

```json
{
  "created_at": "2019-08-24T14:15:22Z",
  "description": "string",
  "enabled": true,
  "env_name": "string",
  "file_path": "string",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "string",
  "updated_at": "2019-08-24T14:15:22Z"
}
```

### Responses [#responses-5]

| Status | Meaning                                                 | Description | Schema                                                                      |
| ------ | ------------------------------------------------------- | ----------- | --------------------------------------------------------------------------- |
| 200    | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK          | [codersdk.UserSecret](/beta-docs/reference/api/schemas/#codersdkusersecret) |

To perform this operation, you must be authenticated. [Learn more](/beta-docs/reference/api/authentication/).
