Infisical Secrets API

The Secrets API from Infisical — 14 operation(s) for secrets.

Operations 25

POST /api/v3/secrets/tags/{secretName}
DELETE /api/v3/secrets/tags/{secretName}
GET /api/v3/secrets/raw
GET /api/v3/secrets/raw/id/{secretId}
GET /api/v3/secrets/raw/{secretName}
POST /api/v3/secrets/raw/{secretName}
PATCH /api/v3/secrets/raw/{secretName}
DELETE /api/v3/secrets/raw/{secretName}
POST /api/v3/secrets/move
POST /api/v3/secrets/batch/raw
PATCH /api/v3/secrets/batch/raw
DELETE /api/v3/secrets/batch/raw
GET /api/v4/secrets #
GET /api/v4/secrets/id/{secretId} #
GET /api/v4/secrets/{secretName} #
POST /api/v4/secrets/{secretName} #
PATCH /api/v4/secrets/{secretName} #
DELETE /api/v4/secrets/{secretName} #
POST /api/v4/secrets/move #
POST /api/v4/secrets/duplicate #
POST /api/v4/secrets/batch #
PATCH /api/v4/secrets/batch #
DELETE /api/v4/secrets/batch #
GET /api/v4/secrets/{secretName}/reference-dependency-tree #
GET /api/v4/secrets/{secretName}/secret-reference-tree #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/infisical-secrets-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

infisical-secrets-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Infisical Admin Secrets API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: Secrets
paths:
  /api/v3/secrets/tags/{secretName}:
    post:
      tags:
      - Secrets
      description: Attach tags to a secret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                projectSlug:
                  type: string
                  description: The slug of the project where the secret is located.
                environment:
                  type: string
                  description: The slug of the environment where the secret is located
                secretPath:
                  type: string
                  default: /
                  description: The path of the secret to attach tags to.
                type:
                  type: string
                  enum:
                  - shared
                  - personal
                  default: shared
                  description: The type of the secret to attach tags to. (shared/personal)
                tagSlugs:
                  type: array
                  items:
                    type: string
                  minItems: 1
                  description: An array of existing tag slugs to attach to the secret.
              required:
              - projectSlug
              - environment
              - tagSlugs
              additionalProperties: false
      parameters:
      - schema:
          type: string
          minLength: 1
        in: path
        name: secretName
        required: true
        description: The name of the secret to attach tags to.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      version:
                        type: number
                        default: 1
                      type:
                        type: string
                        default: shared
                      secretKeyCiphertext:
                        type: string
                      secretKeyIV:
                        type: string
                      secretKeyTag:
                        type: string
                      secretValueCiphertext:
                        type: string
                      secretValueIV:
                        type: string
                      secretValueTag:
                        type: string
                      secretCommentCiphertext:
                        type:
                        - string
                        - 'null'
                      secretCommentIV:
                        type:
                        - string
                        - 'null'
                      secretCommentTag:
                        type:
                        - string
                        - 'null'
                      secretReminderNote:
                        type:
                        - string
                        - 'null'
                      secretReminderRepeatDays:
                        type:
                        - number
                        - 'null'
                      skipMultilineEncoding:
                        type:
                        - boolean
                        - 'null'
                        default: false
                      algorithm:
                        type: string
                        default: aes-256-gcm
                      keyEncoding:
                        type: string
                        default: utf8
                      metadata: {}
                      userId:
                        type:
                        - string
                        - 'null'
                        format: uuid
                      folderId:
                        type: string
                        format: uuid
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      tags:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            slug:
                              type: string
                            color:
                              type:
                              - string
                              - 'null'
                            name:
                              type: string
                          required:
                          - id
                          - slug
                          - name
                          additionalProperties: false
                    required:
                    - id
                    - secretKeyCiphertext
                    - secretKeyIV
                    - secretKeyTag
                    - secretValueCiphertext
                    - secretValueIV
                    - secretValueTag
                    - folderId
                    - createdAt
                    - updatedAt
                    - tags
                    additionalProperties: false
                required:
                - secret
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    delete:
      tags:
      - Secrets
      description: Detach tags from a secret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                projectSlug:
                  type: string
                  description: The slug of the project where the secret is located.
                environment:
                  type: string
                  description: The slug of the environment where the secret is located.
                secretPath:
                  type: string
                  default: /
                  description: The path of the secret to detach tags from.
                type:
                  type: string
                  enum:
                  - shared
                  - personal
                  default: shared
                  description: The type of the secret to attach tags to. (shared/personal)
                tagSlugs:
                  type: array
                  items:
                    type: string
                  minItems: 1
                  description: An array of existing tag slugs to detach from the secret.
              required:
              - projectSlug
              - environment
              - tagSlugs
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: secretName
        required: true
        description: The name of the secret to detach tags from.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      version:
                        type: number
                        default: 1
                      type:
                        type: string
                        default: shared
                      secretKeyCiphertext:
                        type: string
                      secretKeyIV:
                        type: string
                      secretKeyTag:
                        type: string
                      secretValueCiphertext:
                        type: string
                      secretValueIV:
                        type: string
                      secretValueTag:
                        type: string
                      secretCommentCiphertext:
                        type:
                        - string
                        - 'null'
                      secretCommentIV:
                        type:
                        - string
                        - 'null'
                      secretCommentTag:
                        type:
                        - string
                        - 'null'
                      secretReminderNote:
                        type:
                        - string
                        - 'null'
                      secretReminderRepeatDays:
                        type:
                        - number
                        - 'null'
                      skipMultilineEncoding:
                        type:
                        - boolean
                        - 'null'
                        default: false
                      algorithm:
                        type: string
                        default: aes-256-gcm
                      keyEncoding:
                        type: string
                        default: utf8
                      metadata: {}
                      userId:
                        type:
                        - string
                        - 'null'
                        format: uuid
                      folderId:
                        type: string
                        format: uuid
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      tags:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            slug:
                              type: string
                            color:
                              type:
                              - string
                              - 'null'
                            name:
                              type: string
                          required:
                          - id
                          - slug
                          - name
                          additionalProperties: false
                    required:
                    - id
                    - secretKeyCiphertext
                    - secretKeyIV
                    - secretKeyTag
                    - secretValueCiphertext
                    - secretValueIV
                    - secretValueTag
                    - folderId
                    - createdAt
                    - updatedAt
                    - tags
                    additionalProperties: false
                required:
                - secret
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v3/secrets/raw:
    get:
      tags:
      - Secrets
      description: List secrets
      parameters:
      - schema:
          type: string
        in: query
        name: metadataFilter
        required: false
        description: Unencrypted secret metadata key-value pairs used to filter secrets. Only metadata with unencrypted values is supported. When querying for multiple metadata pairs, the query is treated as an AND operation. Secret metadata format is key=value1,value=value2|key=value3,value=value4.
      - schema:
          type: string
        in: query
        name: workspaceId
        required: false
        description: The ID of the project to list secrets from.
      - schema:
          type: string
        in: query
        name: workspaceSlug
        required: false
        description: The slug of the project to list secrets from. This parameter is only applicable by machine identities.
      - schema:
          type: string
        in: query
        name: environment
        required: false
        description: The slug of the environment to list secrets from.
      - schema:
          type: string
          default: /
        in: query
        name: secretPath
        required: false
        description: The secret path to list secrets from.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'true'
        in: query
        name: viewSecretValue
        required: false
        description: Whether or not to retrieve the secret value.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: expandSecretReferences
        required: false
        description: Whether or not to expand secret references.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: recursive
        required: false
        description: Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: include_imports
        required: false
        description: Weather to include imported secrets or not.
      - schema:
          type: string
        in: query
        name: tagSlugs
        required: false
        description: The comma separated tag slugs to filter secrets.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secrets:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        _id:
                          type: string
                        workspace:
                          type: string
                        environment:
                          type: string
                        version:
                          type: number
                        type:
                          type: string
                        secretKey:
                          type: string
                        secretValue:
                          type: string
                        secretComment:
                          type: string
                        secretReminderNote:
                          type:
                          - string
                          - 'null'
                        secretReminderRepeatDays:
                          type:
                          - number
                          - 'null'
                        skipMultilineEncoding:
                          type:
                          - boolean
                          - 'null'
                          default: false
                        createdAt:
                          type: string
                          format: date-time
                        updatedAt:
                          type: string
                          format: date-time
                        actor:
                          type:
                          - object
                          - 'null'
                          properties:
                            actorId:
                              type:
                              - string
                              - 'null'
                            actorType:
                              type:
                              - string
                              - 'null'
                            name:
                              type:
                              - string
                              - 'null'
                            membershipId:
                              type:
                              - string
                              - 'null'
                            groupId:
                              type:
                              - string
                              - 'null'
                          additionalProperties: false
                        isRotatedSecret:
                          type: boolean
                        rotationId:
                          type:
                          - string
                          - 'null'
                          format: uuid
                        secretPath:
                          type: string
                        secretValueHidden:
                          type: boolean
                        secretMetadata:
                          type: array
                          items:
                            type: object
                            properties:
                              key:
                                type: string
                                minLength: 1
                                maxLength: 255
                              value:
                                type: string
                                maxLength: 1020
                                default: ''
                              isEncrypted:
                                type: boolean
                                default: false
                            required:
                            - key
                            additionalProperties: false
                        tags:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                              slug:
                                type: string
                              color:
                                type:
                                - string
                                - 'null'
                              name:
                                type: string
                            required:
                            - id
                            - slug
                            - name
                            additionalProperties: false
                      required:
                      - id
                      - _id
                      - workspace
                      - environment
                      - version
                      - type
                      - secretKey
                      - secretValue
                      - secretComment
                      - createdAt
                      - updatedAt
                      - secretValueHidden
                      additionalProperties: false
                  imports:
                    type: array
                    items:
                      type: object
                      properties:
                        secretPath:
                          type: string
                        environment:
                          type: string
                        folderId:
                          type: string
                        secrets:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                              _id:
                                type: string
                              workspace:
                                type: string
                              environment:
                                type: string
                              version:
                                type: number
                              type:
                                type: string
                              secretKey:
                                type: string
                              secretValue:
                                type: string
                              secretComment:
                                type: string
                              secretReminderNote:
                                type:
                                - string
                                - 'null'
                              secretReminderRepeatDays:
                                type:
                                - number
                                - 'null'
                              skipMultilineEncoding:
                                type:
                                - boolean
                                - 'null'
                                default: false
                              actor:
                                type:
                                - object
                                - 'null'
                                properties:
                                  actorId:
                                    type:
                                    - string
                                    - 'null'
                                  actorType:
                                    type:
                                    - string
                                    - 'null'
                                  name:
                                    type:
                                    - string
                                    - 'null'
                                  membershipId:
                                    type:
                                    - string
                                    - 'null'
                                  groupId:
                                    type:
                                    - string
                                    - 'null'
                                additionalProperties: false
                              isRotatedSecret:
                                type: boolean
                              rotationId:
                                type:
                                - string
                                - 'null'
                                format: uuid
                              secretValueHidden:
                                type: boolean
                              secretMetadata:
                                type: array
                                items:
                                  type: object
                                  properties:
                                    key:
                                      type: string
                                      minLength: 1
                                      maxLength: 255
                                    value:
                                      type: string
                                      maxLength: 1020
                                      default: ''
                                    isEncrypted:
                                      type: boolean
                                      default: false
                                  required:
                                  - key
                                  additionalProperties: false
                            required:
                            - id
                            - _id
                            - workspace
                            - environment
                            - version
                            - type
                            - secretKey
                            - secretValue
                            - secretComment
                            - secretValueHidden
                            additionalProperties: false
                      required:
                      - secretPath
                      - environment
                      - secrets
                      additionalProperties: false
                required:
                - secrets
                additionalProperties: false
        '304':
          description: Default Response
          content:
            application/json:
              schema: {}
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
       

# --- truncated at 32 KB (271 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-secrets-api-openapi.yml