Rotate a secret (sync or async)
const url = 'https://example.com/v1/secrets/example/rotate?scopeKind=tenant';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"scope":{"kind":"tenant","tenantId":"example"},"envName":"example","newValue":"example","revokeOldAfterMs":1}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url 'https://example.com/v1/secrets/example/rotate?scopeKind=tenant' \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "scope": { "kind": "tenant", "tenantId": "example" }, "envName": "example", "newValue": "example", "revokeOldAfterMs": 1 }'Requires the secrets:rotate capability. The scope comes from body scope, else from scopeKind + scopeId in the query; one of them is required, and when both are present they must name the same scope. Authorization checks that scope. Sync providers return 201 with { kind: "sync", newVersionId, oldVersionId, oldVersionRevokedAt? }. Async providers return 202 with { kind: "async", rotationId, statusUrl, eventsUrl }; poll via GET /v1/secrets/:name/rotations/:rotationId or subscribe via SSE at the events URL. kind is the discriminant.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Secret name (opaque string within the tenant + envName).
Query Parameters
Section titled “Query Parameters”Per-environment slug. [a-z][a-z0-9-]{0,62} — RFC-1035-like label.
Alternative to body envName. When both are present they must match (400 env-name-mismatch).
Discriminator for the ?scopeKind + ?scopeId + ?inherit triplet. Tenant carries no id (implicit from session); org/project require scopeId.
Alternative to body scope (with scopeId). When both are present they must name the same scope (400 scope-mismatch).
Required IF scopeKind is org or project. MUST be absent if scopeKind=tenant (tenant is implicit from the session). Malformed combinations return 400 scope-invalid.
Header Parameters
Section titled “Header Parameters”Caller-supplied idempotency key. Retries with the same key return the original response byte-identical (per docs/API-ROUTE-CONVENTIONS.md §3.1).
Request Body
Section titled “Request Body”object
Per-environment slug. [a-z][a-z0-9-]{0,62} — RFC-1035-like label.
Responses
Section titled “Responses”Sync rotation complete.
object
Example
{ "kind": "sync"}Async rotation accepted; poll or subscribe.
object
Example
{ "kind": "async"}Malformed request body.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Bearer token missing secrets:rotate capability.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Unknown secret.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Idempotency-Key was reused with a different body, or resource-state conflict.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Server error (unmapped domain code or framework crash).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}