Infisical Secrets API

The Secrets API from Infisical — 14 operation(s) for secrets.

OpenAPI Specification

infisical-secrets-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Infisical Admin Secrets API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: Secrets
paths:
  /api/v3/secrets/tags/{secretName}:
    post:
      tags:
      - Secrets
      description: Attach tags to a secret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                projectSlug:
                  type: string
                  description: The slug of the project where the secret is located.
                environment:
                  type: string
                  description: The slug of the environment where the secret is located
                secretPath:
                  type: string
                  default: /
                  description: The path of the secret to attach tags to.
                type:
                  type: string
                  enum:
                  - shared
                  - personal
                  default: shared
                  description: The type of the secret to attach tags to. (shared/personal)
                tagSlugs:
                  type: array
                  items:
                    type: string
                  minItems: 1
                  description: An array of existing tag slugs to attach to the secret.
              required:
              - projectSlug
              - environment
              - tagSlugs
              additionalProperties: false
      parameters:
      - schema:
          type: string
          minLength: 1
        in: path
        name: secretName
        required: true
        description: The name of the secret to attach tags to.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      version:
                        type: number
                        default: 1
                      type:
                        type: string
                        default: shared
                      secretKeyCiphertext:
                        type: string
                      secretKeyIV:
                        type: string
                      secretKeyTag:
                        type: string
                      secretValueCiphertext:
                        type: string
                      secretValueIV:
                        type: string
                      secretValueTag:
                        type: string
                      secretCommentCiphertext:
                        type: string
                        nullable: true
                      secretCommentIV:
                        type: string
                        nullable: true
                      secretCommentTag:
                        type: string
                        nullable: true
                      secretReminderNote:
                        type: string
                        nullable: true
                      secretReminderRepeatDays:
                        type: number
                        nullable: true
                      skipMultilineEncoding:
                        type: boolean
                        default: false
                        nullable: true
                      algorithm:
                        type: string
                        default: aes-256-gcm
                      keyEncoding:
                        type: string
                        default: utf8
                      metadata:
                        nullable: true
                      userId:
                        type: string
                        format: uuid
                        nullable: true
                      folderId:
                        type: string
                        format: uuid
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      tags:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            slug:
                              type: string
                            color:
                              type: string
                              nullable: true
                            name:
                              type: string
                          required:
                          - id
                          - slug
                          - name
                          additionalProperties: false
                    required:
                    - id
                    - secretKeyCiphertext
                    - secretKeyIV
                    - secretKeyTag
                    - secretValueCiphertext
                    - secretValueIV
                    - secretValueTag
                    - folderId
                    - createdAt
                    - updatedAt
                    - tags
                    additionalProperties: false
                required:
                - secret
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    delete:
      tags:
      - Secrets
      description: Detach tags from a secret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                projectSlug:
                  type: string
                  description: The slug of the project where the secret is located.
                environment:
                  type: string
                  description: The slug of the environment where the secret is located.
                secretPath:
                  type: string
                  default: /
                  description: The path of the secret to detach tags from.
                type:
                  type: string
                  enum:
                  - shared
                  - personal
                  default: shared
                  description: The type of the secret to attach tags to. (shared/personal)
                tagSlugs:
                  type: array
                  items:
                    type: string
                  minItems: 1
                  description: An array of existing tag slugs to detach from the secret.
              required:
              - projectSlug
              - environment
              - tagSlugs
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: secretName
        required: true
        description: The name of the secret to detach tags from.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      version:
                        type: number
                        default: 1
                      type:
                        type: string
                        default: shared
                      secretKeyCiphertext:
                        type: string
                      secretKeyIV:
                        type: string
                      secretKeyTag:
                        type: string
                      secretValueCiphertext:
                        type: string
                      secretValueIV:
                        type: string
                      secretValueTag:
                        type: string
                      secretCommentCiphertext:
                        type: string
                        nullable: true
                      secretCommentIV:
                        type: string
                        nullable: true
                      secretCommentTag:
                        type: string
                        nullable: true
                      secretReminderNote:
                        type: string
                        nullable: true
                      secretReminderRepeatDays:
                        type: number
                        nullable: true
                      skipMultilineEncoding:
                        type: boolean
                        default: false
                        nullable: true
                      algorithm:
                        type: string
                        default: aes-256-gcm
                      keyEncoding:
                        type: string
                        default: utf8
                      metadata:
                        nullable: true
                      userId:
                        type: string
                        format: uuid
                        nullable: true
                      folderId:
                        type: string
                        format: uuid
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      tags:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            slug:
                              type: string
                            color:
                              type: string
                              nullable: true
                            name:
                              type: string
                          required:
                          - id
                          - slug
                          - name
                          additionalProperties: false
                    required:
                    - id
                    - secretKeyCiphertext
                    - secretKeyIV
                    - secretKeyTag
                    - secretValueCiphertext
                    - secretValueIV
                    - secretValueTag
                    - folderId
                    - createdAt
                    - updatedAt
                    - tags
                    additionalProperties: false
                required:
                - secret
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v3/secrets/raw:
    get:
      tags:
      - Secrets
      description: List secrets
      parameters:
      - schema:
          type: string
        in: query
        name: metadataFilter
        required: false
        description: Unencrypted secret metadata key-value pairs used to filter secrets. Only metadata with unencrypted values is supported. When querying for multiple metadata pairs, the query is treated as an AND operation. Secret metadata format is key=value1,value=value2|key=value3,value=value4.
      - schema:
          type: string
        in: query
        name: workspaceId
        required: false
        description: The ID of the project to list secrets from.
      - schema:
          type: string
        in: query
        name: workspaceSlug
        required: false
        description: The slug of the project to list secrets from. This parameter is only applicable by machine identities.
      - schema:
          type: string
        in: query
        name: environment
        required: false
        description: The slug of the environment to list secrets from.
      - schema:
          type: string
          default: /
        in: query
        name: secretPath
        required: false
        description: The secret path to list secrets from.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'true'
        in: query
        name: viewSecretValue
        required: false
        description: Whether or not to retrieve the secret value.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: expandSecretReferences
        required: false
        description: Whether or not to expand secret references.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: recursive
        required: false
        description: Whether or not to fetch all secrets from the specified base path, and all of its subdirectories. Note, the max depth is 20 deep.
      - schema:
          type: string
          enum:
          - 'true'
          - 'false'
          default: 'false'
        in: query
        name: include_imports
        required: false
        description: Weather to include imported secrets or not.
      - schema:
          type: string
        in: query
        name: tagSlugs
        required: false
        description: The comma separated tag slugs to filter secrets.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secrets:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        _id:
                          type: string
                        workspace:
                          type: string
                        environment:
                          type: string
                        version:
                          type: number
                        type:
                          type: string
                        secretKey:
                          type: string
                        secretValue:
                          type: string
                        secretComment:
                          type: string
                        secretReminderNote:
                          type: string
                          nullable: true
                        secretReminderRepeatDays:
                          type: number
                          nullable: true
                        skipMultilineEncoding:
                          type: boolean
                          default: false
                          nullable: true
                        createdAt:
                          type: string
                          format: date-time
                        updatedAt:
                          type: string
                          format: date-time
                        actor:
                          type: object
                          properties:
                            actorId:
                              type: string
                              nullable: true
                            actorType:
                              type: string
                              nullable: true
                            name:
                              type: string
                              nullable: true
                            membershipId:
                              type: string
                              nullable: true
                            groupId:
                              type: string
                              nullable: true
                          additionalProperties: false
                          nullable: true
                        isRotatedSecret:
                          type: boolean
                        rotationId:
                          type: string
                          format: uuid
                          nullable: true
                        secretPath:
                          type: string
                        secretValueHidden:
                          type: boolean
                        secretMetadata:
                          type: array
                          items:
                            type: object
                            properties:
                              key:
                                type: string
                                minLength: 1
                                maxLength: 255
                              value:
                                type: string
                                maxLength: 1020
                                default: ''
                              isEncrypted:
                                type: boolean
                                default: false
                            required:
                            - key
                            additionalProperties: false
                        tags:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                              slug:
                                type: string
                              color:
                                type: string
                                nullable: true
                              name:
                                type: string
                            required:
                            - id
                            - slug
                            - name
                            additionalProperties: false
                      required:
                      - id
                      - _id
                      - workspace
                      - environment
                      - version
                      - type
                      - secretKey
                      - secretValue
                      - secretComment
                      - createdAt
                      - updatedAt
                      - secretValueHidden
                      additionalProperties: false
                  imports:
                    type: array
                    items:
                      type: object
                      properties:
                        secretPath:
                          type: string
                        environment:
                          type: string
                        folderId:
                          type: string
                        secrets:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                              _id:
                                type: string
                              workspace:
                                type: string
                              environment:
                                type: string
                              version:
                                type: number
                              type:
                                type: string
                              secretKey:
                                type: string
                              secretValue:
                                type: string
                              secretComment:
                                type: string
                              secretReminderNote:
                                type: string
                                nullable: true
                              secretReminderRepeatDays:
                                type: number
                                nullable: true
                              skipMultilineEncoding:
                                type: boolean
                                default: false
                                nullable: true
                              actor:
                                type: object
                                properties:
                                  actorId:
                                    type: string
                                    nullable: true
                                  actorType:
                                    type: string
                                    nullable: true
                                  name:
                                    type: string
                                    nullable: true
                                  membershipId:
                                    type: string
                                    nullable: true
                                  groupId:
                                    type: string
                                    nullable: true
                                additionalProperties: false
                                nullable: true
                              isRotatedSecret:
                                type: boolean
                              rotationId:
                                type: string
                                format: uuid
                                nullable: true
                              secretValueHidden:
                                type: boolean
                              secretMetadata:
                                type: array
                                items:
                                  type: object
                                  properties:
                                    key:
                                      type: string
                                      minLength: 1
                                      maxLength: 255
                                    value:
                                      type: string
                                      maxLength: 1020
                                      default: ''
                                    isEncrypted:
                                      type: boolean
                                      default: false
                                  required:
                                  - key
                                  additionalProperties: false
                            required:
                            - id
                            - _id
                            - workspace
                            - environment
                            - version
                            - type
                            - secretKey
                            - secretValue
                            - secretComment
                            - secretValueHidden
                            additionalProperties: false
                      required:
                      - secretPath
                      - environment
                      - secrets
                      additionalProperties: false
                required:
                - secrets
                additionalProperties: false
        '304':
          description: Default Response
          content:
            application/json:
              schema: {}
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    t

# --- truncated at 32 KB (265 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-secrets-api-openapi.yml