Skip to content

Create or update an environment secret

PUT
/repos/{owner}/{repo}/environments/{environment_name}/secrets/{secret_name}

Creates or updates an environment secret with an encrypted value. Encrypt your secret using LibSodium. For more information, see “Encrypting secrets for the REST API.”

Authenticated users must have collaborator access to a repository to create, update, or read secrets.

OAuth tokens and personal access tokens (classic) need the repo scope to use this endpoint.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

environment_name
required
string

The name of the environment. The name must be URL encoded. For example, any slashes in the name must be replaced with %2F.

secret_name
required
string

The name of the secret.

Media type application/json
object
encrypted_value
required

Value for your secret, encrypted with LibSodium using the public key retrieved from the Get an environment public key endpoint.

string
/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})$/
key_id
required

ID of the key you used to encrypt the secret.

string
Examples
Example default
{
"encrypted_value": "c2VjcmV0",
"key_id": "012345678912345678"
}

Response when creating a secret

Media type application/json
Empty Object

An object without any properties.

object
Examples
Example default
null

Response when updating a secret