Skip to content

Create or update an organization secret

PUT
/orgs/{org}/agents/secrets/{secret_name}

Creates or updates an organization secret with an encrypted value. Encrypt your secret using LibSodium. For more information, see “Encrypting secrets for the REST API.”

Authenticated users must have collaborator access to a repository to create, update, or read secrets.

OAuth tokens and personal access tokens (classic) need the admin:org scope to use this endpoint. If the repository is private, OAuth tokens and personal access tokens (classic) need the repo scope to use this endpoint.

API method documentation

org
required
string

The organization name. The name is not case sensitive.

secret_name
required
string

The name of the secret.

Media type application/json
object
encrypted_value
required

Value for your secret, encrypted with LibSodium using the public key retrieved from the Get an organization public key endpoint.

string
/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})$/
key_id
required

ID of the key you used to encrypt the secret.

string
visibility
required

Which type of organization repositories have access to the organization secret. selected means only the repositories specified by selected_repository_ids can access the secret.

string
Allowed values: all private selected
selected_repository_ids

An array of repository ids that can access the organization secret. You can only provide a list of repository ids when the visibility is set to selected. You can manage the list of selected repositories using the List selected repositories for an organization secret, Set selected repositories for an organization secret, and Remove selected repository from an organization secret endpoints.

Array<integer>
Examples
Example default
{
"encrypted_value": "c2VjcmV0",
"key_id": "012345678912345678",
"visibility": "selected",
"selected_repository_ids": [
1296269,
1296280
]
}

Response when creating a secret

Media type application/json
Empty Object

An object without any properties.

object
Examples
Example default
null

Response when updating a secret