Cumulus TalosDocs
Open Talos
On this page

secrets.put

Create a secret or add a new version

Request

PUT /api/v1/secrets/{secret_id}

  • MCP: secrets_put
  • SDK: client.secrets.put (SDK path arguments use path; MCP uses params).
  • Minimum API key role: admin.
  • Idempotency: required_header. Send an Idempotency-Key header; MCP uses idempotency_key. Reuse it after an unknown outcome.

Needs an admin key. kind sip_auth holds a SIP trunk password (trunks_create auth_secret), webhook_signing a webhook signing secret, http_auth an HTTP action credential. The response never contains the value; reference the secret as {id, version: current_version}. For Basis Theory use kind http_auth, then drafts_edit action.put with auth {scheme: header, header_name: BT-PROXY-KEY, secret_ref: {id, version}}. Remove the key query parameter from the action URL; never echo the value. Proxy access does not establish tokenization permissions.

Input schema

json
{
  "parameters": [
    {
      "name": "secret_id",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string",
        "minLength": 1,
        "maxLength": 128,
        "pattern": "^[a-z0-9][a-z0-9_-]*$"
      }
    },
    {
      "name": "Idempotency-Key",
      "in": "header",
      "required": true,
      "schema": {
        "type": "string",
        "minLength": 1,
        "maxLength": 256
      }
    }
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsPutRequest"
        }
      }
    }
  }
}

Responses

json
{
  "200": {
    "description": "Create a secret or add a new version",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretMetadata"
        }
      }
    }
  },
  "4XX": {
    "description": "Typed error (ApiError)",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ApiError"
        }
      }
    }
  },
  "5XX": {
    "description": "Typed error (ApiError)",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ApiError"
        }
      }
    }
  }
}

Referenced schemas

json
{
  "components": {
    "schemas": {
      "SecretsPutRequest": {
        "type": "object",
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "webhook_signing",
              "http_auth",
              "sip_auth"
            ]
          },
          "value": {
            "type": "string",
            "minLength": 1,
            "maxLength": 16384
          }
        },
        "required": [
          "kind",
          "value"
        ],
        "additionalProperties": false
      },
      "SecretMetadata": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128,
            "pattern": "^[a-z0-9][a-z0-9_-]*$"
          },
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128,
            "pattern": "^[a-z0-9][a-z0-9_-]*$"
          },
          "kind": {
            "type": "string",
            "enum": [
              "webhook_signing",
              "http_auth",
              "sip_auth"
            ]
          },
          "current_version": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "versions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "version": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 128
                },
                "created_at": {
                  "type": "string",
                  "format": "date-time"
                }
              },
              "required": [
                "version",
                "created_at"
              ],
              "additionalProperties": false
            },
            "minItems": 1
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "name",
          "kind",
          "current_version",
          "versions",
          "created_at"
        ],
        "additionalProperties": false
      },
      "ApiError": {
        "type": "object",
        "properties": {
          "error": {
            "type": "object",
            "properties": {
              "code": {
                "type": "string",
                "enum": [
                  "unauthenticated",
                  "forbidden",
                  "not_found",
                  "conflict",
                  "invalid_request",
                  "idempotency_conflict",
                  "policy_denied",
                  "capability_unavailable",
                  "provider_unavailable",
                  "knowledge_unavailable",
                  "publication_invalid",
                  "run_not_active",
                  "rate_limited",
                  "outcome_unknown",
                  "internal"
                ]
              },
              "message": {
                "type": "string"
              },
              "retryable": {
                "type": "boolean"
              },
              "outcome": {
                "type": "string",
                "enum": [
                  "none",
                  "unknown"
                ]
              },
              "details": {
                "type": "object",
                "additionalProperties": {}
              }
            },
            "required": [
              "code",
              "message",
              "retryable",
              "outcome"
            ],
            "additionalProperties": false
          }
        },
        "required": [
          "error"
        ],
        "additionalProperties": false
      }
    }
  }
}

Errors and recovery

See API error handling and Troubleshooting.

Content version 4343528bMarkdown source
secrets.put · Cumulus Talos docs