Sync secrets against a deployment
const url = 'https://example.com/v1/deployments/example/secrets';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"envName":"example","secrets":[{"name":"example","ref":"example"}]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/deployments/example/secrets \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "envName": "example", "secrets": [ { "name": "example", "ref": "example" } ] }'Deployment-scoped bulk secret sync. Body carries { envName, secrets: Array<{ name, ref } | { name, value }> }. { name, ref } entries validate against SecretBinding.get — no bytes cross the wire; missing → 404 secret-not-found. { name, value } entries write via SecretBinding.set with writeMode: add-version + tags.deployment = deploymentId and return the created reference. The write scope is derived from the deployment record itself (tenant scope, or project scope when the deployment carries a projectId) and CANNOT be overridden on the wire. Requires the secrets:write capability. Idempotency-Key applies.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Deployment id assigned by the ledger at register time.
Header Parameters
Section titled “Header Parameters”Caller-supplied idempotency key. Retries with the same key return the original response byte-identical (per docs/API-ROUTE-CONVENTIONS.md §3.1).
Request Bodyrequired
Section titled “Request Bodyrequired”object
Per-environment slug. [a-z][a-z0-9-]{0,62} — RFC-1035-like label.
Zero or more secret entries. Each entry MUST set exactly one of ref (validate-only) or value (write new version).
object
Opaque reference to an existing secret record — validated via SecretBinding.get; no bytes cross the wire.
object
Plaintext secret value written via SecretBinding.set with writeMode: add-version. The response returns only the framework-generated reference.
Examplegenerated
{ "envName": "example", "secrets": [ { "name": "example", "ref": "example" } ]}Responses
Section titled “Responses”Sync complete.
object
object
Opaque reference — either echoed from the request ({ name, ref } entries) or freshly minted (secret:<envName>/<name>#<version> for { name, value } entries).
Examplegenerated
{ "resolved": 1, "added": 1, "references": [ { "name": "example", "ref": "example", "version": 1 } ]}Malformed request body.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Bearer token missing secrets:write capability.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}No deployment with that id, or referenced secret does not exist.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Idempotency-Key was reused with a different body, or resource-state conflict.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Server error (unmapped domain code or framework crash).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}