Skip to main content
POST
Create or update a secret

Authorizations

Authorization
string
header
required

Your ara_ API key from Settings > Ara API. Keys are capability-scoped: run, plugins:read, secrets:read, secrets:write, sessions:read, knowledge:read, repos:read, repos:write, reviews:read, reviews:write, analytics:read, org:read, org:write, attachments:read, attachments:write, plugins:write, guardrails:read, guardrails:write.

Path Parameters

orgId
string
required

Organization id or slug. Resolve it with GET /v3/self.

Body

application/json
name
string
required

Uppercase identifier, e.g. NPM_TOKEN.

value
string
required

The secret value. Stored encrypted and never returned.

note
string

Optional usage guidance for agents and workspace members. Include the repository name when the secret is intended for one codebase.

Maximum string length: 2000
scope
enum<string>
default:user
Available options:
organization,
user,
repo
repo
string

Deprecated context field for the repo compatibility scope. The value is stored workspace-wide.

provider
enum<string>

Deprecated provider context for the repo compatibility scope.

Available options:
github,
gitlab

Response

Secret stored.