> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://reference.flatfile.com/api-reference/secrets/upsert/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://reference.flatfile.com/_mcp/server. # Upsert a Secret POST https://api.x.flatfile.com/v1/secrets Content-Type: application/json Insert or Update a Secret by name for environment or space Reference: https://reference.flatfile.com/api-reference/secrets/upsert ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Body (application/json) This endpoint expects a WriteSecret. - `name` (string, required) — The reference name for a secret. - `value` (string, required) — The secret value. This is hidden in the UI. - `environmentId` (string, optional) — The Environment of the secret. - `spaceId` (string, optional) — The Space of the secret. - `actorId` (ActorIdUnion, optional) — The Actor of the secret. ## Response ### 200 - `data` (list of Secret, required) ## Errors ### 400 Bad Request Error - `errors` (list of Error, required) ### 404 Not Found Error - `errors` (list of Error, required) ## Types ### ActorIdUnion ### Secret The value of a secret - `id` (string, required) — The ID of the secret. - `name` (string, required) — The reference name for a secret. - `value` (string, required) — The secret value. This is hidden in the UI. - `actorId` (ActorIdUnion, optional) — The Actor of the secret. - `environmentId` (string, optional) — The Environment of the secret. - `spaceId` (string, optional) — The Space of the secret. ### Error - `message` (string, required) - `key` (string, optional) ## Examples **Request** ```json { "name": "My Secret", "value": "Sup3r$ecret\\/alue!", "environmentId": "us_env_YOUR_ID", "spaceId": "us_sp_YOUR_ID", "actorId": "us_usr_YOUR_ID" } ``` **Response** ```json { "data": [ { "id": "us_sec_YOUR_ID", "name": "My Secret", "value": "Sup3r$ecret\\/alue!", "actorId": "us_usr_YOUR_ID", "environmentId": "us_env_YOUR_ID", "spaceId": "us_sp_YOUR_ID" } ] } ``` **SDK Code** ```python Example0 import requests url = "https://api.x.flatfile.com/v1/secrets" payload = { "name": "My Secret", "value": "Sup3r$ecret\/alue!", "environmentId": "us_env_YOUR_ID", "spaceId": "us_sp_YOUR_ID", "actorId": "us_usr_YOUR_ID" } headers = { "X-Disable-Hooks": "true", "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```typescript Example0 import { FlatfileClient } from "@flatfile/api"; const client = new FlatfileClient({ token: "YOUR_TOKEN" }); await client.secrets.upsert({ name: "My Secret", value: "Sup3r$ecret\\/alue!", environmentId: "us_env_YOUR_ID", spaceId: "us_sp_YOUR_ID", actorId: "us_usr_YOUR_ID" }); ``` ```go Example0 package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.x.flatfile.com/v1/secrets" payload := strings.NewReader("{\n \"name\": \"My Secret\",\n \"value\": \"Sup3r$ecret\\\\/alue!\",\n \"environmentId\": \"us_env_YOUR_ID\",\n \"spaceId\": \"us_sp_YOUR_ID\",\n \"actorId\": \"us_usr_YOUR_ID\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("X-Disable-Hooks", "true") req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Example0 require 'uri' require 'net/http' url = URI("https://api.x.flatfile.com/v1/secrets") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["X-Disable-Hooks"] = 'true' request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"name\": \"My Secret\",\n \"value\": \"Sup3r$ecret\\\\/alue!\",\n \"environmentId\": \"us_env_YOUR_ID\",\n \"spaceId\": \"us_sp_YOUR_ID\",\n \"actorId\": \"us_usr_YOUR_ID\"\n}" response = http.request(request) puts response.read_body ``` ```java Example0 import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.x.flatfile.com/v1/secrets") .header("X-Disable-Hooks", "true") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"name\": \"My Secret\",\n \"value\": \"Sup3r$ecret\\\\/alue!\",\n \"environmentId\": \"us_env_YOUR_ID\",\n \"spaceId\": \"us_sp_YOUR_ID\",\n \"actorId\": \"us_usr_YOUR_ID\"\n}") .asString(); ``` ```php Example0 request('POST', 'https://api.x.flatfile.com/v1/secrets', [ 'body' => '{ "name": "My Secret", "value": "Sup3r$ecret\\\\/alue!", "environmentId": "us_env_YOUR_ID", "spaceId": "us_sp_YOUR_ID", "actorId": "us_usr_YOUR_ID" }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', 'X-Disable-Hooks' => 'true', ], ]); echo $response->getBody(); ``` ```csharp Example0 using RestSharp; var client = new RestClient("https://api.x.flatfile.com/v1/secrets"); var request = new RestRequest(Method.POST); request.AddHeader("X-Disable-Hooks", "true"); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"name\": \"My Secret\",\n \"value\": \"Sup3r$ecret\\\\/alue!\",\n \"environmentId\": \"us_env_YOUR_ID\",\n \"spaceId\": \"us_sp_YOUR_ID\",\n \"actorId\": \"us_usr_YOUR_ID\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Example0 import Foundation let headers = [ "X-Disable-Hooks": "true", "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = [ "name": "My Secret", "value": "Sup3r$ecret\/alue!", "environmentId": "us_env_YOUR_ID", "spaceId": "us_sp_YOUR_ID", "actorId": "us_usr_YOUR_ID" ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.x.flatfile.com/v1/secrets")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```