Koyeb Secrets API

The Secrets API from Koyeb — 3 operation(s) for secrets.

Operations 7

GET /v1/secrets List Secrets #
POST /v1/secrets Create Secret #
GET /v1/secrets/{id} Get Secret #
DELETE /v1/secrets/{id} Delete Secret #
PUT /v1/secrets/{id} Update Secret #
PATCH /v1/secrets/{id} Update Secret #
POST /v1/secrets/{id}/reveal Reveal Secret #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/koyeb-secrets-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

koyeb-secrets-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Koyeb Rest Secrets API
  description: 'The Koyeb API allows you to interact with the Koyeb platform in a simple, programmatic way using conventional HTTP requests.

    '
  version: 1.0.0
servers:
- url: https://app.koyeb.com
security:
- Bearer: []
tags:
- name: Secrets
paths:
  /v1/secrets:
    get:
      summary: List Secrets
      operationId: ListSecrets
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListSecretsReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: name
        in: query
        required: false
        schema:
          type: string
      - name: limit
        in: query
        required: false
        schema:
          type: string
      - name: offset
        in: query
        required: false
        schema:
          type: string
      - name: types
        description: Filter by secret types
        in: query
        required: false
        style: form
        explode: true
        schema:
          type: array
          items:
            type: string
            enum:
            - SIMPLE
            - REGISTRY
            - MANAGED
      - name: project_id
        description: (Optional) A filter for the project ID
        in: query
        required: false
        schema:
          type: string
      - name: ids
        description: (Optional) Filter on secret ids
        in: query
        required: false
        style: form
        explode: true
        schema:
          type: array
          items:
            type: string
      tags:
      - Secrets
    post:
      summary: Create Secret
      operationId: CreateSecret
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      tags:
      - Secrets
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSecret'
        required: true
  /v1/secrets/{id}:
    get:
      summary: Get Secret
      operationId: GetSecret
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      tags:
      - Secrets
    delete:
      summary: Delete Secret
      operationId: DeleteSecret
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      tags:
      - Secrets
    put:
      summary: Update Secret
      operationId: UpdateSecret
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      - name: update_mask
        in: query
        required: false
        schema:
          type: string
      tags:
      - Secrets
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Secret'
        required: true
    patch:
      summary: Update Secret
      operationId: UpdateSecret2
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      - name: update_mask
        in: query
        required: false
        schema:
          type: string
      tags:
      - Secrets
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Secret'
        required: true
  /v1/secrets/{id}/reveal:
    post:
      summary: Reveal Secret
      operationId: RevealSecret
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RevealSecretReply'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorWithFields'
        '401':
          description: Returned when the token is not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Returned when the user does not have permission to access the resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Returned when the resource does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Returned in case of server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/google.rpc.Status'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      tags:
      - Secrets
      requestBody:
        content:
          application/json:
            schema:
              type: object
        required: true
components:
  schemas:
    DeleteSecretReply:
      type: object
    Secret:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        organization_id:
          type: string
        type:
          $ref: '#/components/schemas/SecretType'
        updated_at:
          type: string
          format: date-time
        created_at:
          type: string
          format: date-time
        project_id:
          type: string
          description: The project ID this secret belongs to. Empty if the secret is organization-level.
        value:
          type: string
        docker_hub_registry:
          $ref: '#/components/schemas/DockerHubRegistryConfiguration'
        private_registry:
          $ref: '#/components/schemas/PrivateRegistryConfiguration'
        digital_ocean_registry:
          $ref: '#/components/schemas/DigitalOceanRegistryConfiguration'
        github_registry:
          $ref: '#/components/schemas/GitHubRegistryConfiguration'
        gitlab_registry:
          $ref: '#/components/schemas/GitLabRegistryConfiguration'
        gcp_container_registry:
          $ref: '#/components/schemas/GCPContainerRegistryConfiguration'
        azure_container_registry:
          $ref: '#/components/schemas/AzureContainerRegistryConfiguration'
        database_role_password:
          $ref: '#/components/schemas/DatabaseRolePassword'
    UpdateSecretReply:
      type: object
      properties:
        secret:
          $ref: '#/components/schemas/Secret'
    CreateSecret:
      type: object
      properties:
        name:
          type: string
        type:
          $ref: '#/components/schemas/SecretType'
        value:
          type: string
        docker_hub_registry:
          $ref: '#/components/schemas/DockerHubRegistryConfiguration'
        private_registry:
          $ref: '#/components/schemas/PrivateRegistryConfiguration'
        digital_ocean_registry:
          $ref: '#/components/schemas/DigitalOceanRegistryConfiguration'
        github_registry:
          $ref: '#/components/schemas/GitHubRegistryConfiguration'
        gitlab_registry:
          $ref: '#/components/schemas/GitLabRegistryConfiguration'
        gcp_container_registry:
          $ref: '#/components/schemas/GCPContainerRegistryConfiguration'
        azure_container_registry:
          $ref: '#/components/schemas/AzureContainerRegistryConfiguration'
        project_id:
          type: string
          title: (Optional) The project ID to associate with the secret
    GitHubRegistryConfiguration:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
    google.rpc.Status:
      type: object
      properties:
        code:
          type: integer
          format: int32
        message:
          type: string
        details:
          type: array
          items:
            $ref: '#/components/schemas/google.protobuf.Any'
    ErrorField:
      type: object
      properties:
        field:
          type: string
        description:
          type: string
    Error:
      type: object
      properties:
        status:
          type: integer
          format: int32
        code:
          type: string
        message:
          type: string
    google.protobuf.Any:
      type: object
      properties:
        '@type':
          type: string
          description: "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n  value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n  URL, or have them precompiled into a binary to avoid any\n  lookup. Therefore, binary compatibility needs to be preserved\n  on changes to types. (Use versioned type names to manage\n  breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics."
      additionalProperties: {}
      description: "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n    Foo foo = ...;\n    Any any;\n    any.PackFrom(foo);\n    ...\n    if (any.UnpackTo(&foo)) {\n      ...\n    }\n\nExample 2: Pack and unpack a message in Java.\n\n    Foo foo = ...;\n    Any any = Any.pack(foo);\n    ...\n    if (any.is(Foo.class)) {\n      foo = any.unpack(Foo.class);\n    }\n\n Example 3: Pack and unpack a message in Python.\n\n    foo = Foo(...)\n    any = Any()\n    any.Pack(foo)\n    ...\n    if any.Is(Foo.DESCRIPTOR):\n      any.Unpack(foo)\n      ...\n\n Example 4: Pack and unpack a message in Go\n\n     foo := &pb.Foo{...}\n     any, err := anypb.New(foo)\n     if err != nil {\n       ...\n     }\n     ...\n     foo := &pb.Foo{}\n     if err := any.UnmarshalTo(foo); err != nil {\n       ...\n     }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\n\nJSON\n====\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n    package google.profile;\n    message Person {\n      string first_name = 1;\n      string last_name = 2;\n    }\n\n    {\n      \"@type\": \"type.googleapis.com/google.profile.Person\",\n      \"firstName\": <string>,\n      \"lastName\": <string>\n    }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n    {\n      \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n      \"value\": \"1.212s\"\n    }"
    DockerHubRegistryConfiguration:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
    DigitalOceanRegistryConfiguration:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
    GitLabRegistryConfiguration:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
    PrivateRegistryConfiguration:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
        url:
          type: string
    RevealSecretReply:
      type: object
      properties:
        value: {}
    ListSecretsReply:
      type: object
      properties:
        secrets:
          type: array
          items:
            $ref: '#/components/schemas/Secret'
        limit:
          type: integer
          format: int64
        offset:
          type: integer
          format: int64
        count:
          type: integer
          format: int64
    SecretType:
      type: string
      enum:
      - SIMPLE
      - REGISTRY
      - MANAGED
      default: SIMPLE
    AzureContainerRegistryConfiguration:
      type: object
      properties:
        registry_name:
          type: string
        username:
          type: string
        password:
          type: string
    DatabaseRolePassword:
      type: object
      properties:
        username:
          type: string
        password:
          type: string
    CreateSecretReply:
      type: object
      properties:
        secret:
          $ref: '#/components/schemas/Secret'
    GCPContainerRegistryConfiguration:
      type: object
      properties:
        keyfile_content:
          type: string
        url:
          type: string
    GetSecretReply:
      type: object
      properties:
        secret:
          $ref: '#/components/schemas/Secret'
    ErrorWithFields:
      type: object
      properties:
        status:
          type: integer
          format: int32
        code:
          type: string
        message:
          type: string
        fields:
          type: array
          items:
            $ref: '#/components/schemas/ErrorField'
  securitySchemes:
    Bearer:
      type: apiKey
      name: Authorization
      in: header
x-tagGroups:
- name: Introduction
  tags:
  - intro
- name: API
  tags:
  - Profile
  - Sessions
  - Users
  - organization
  - Projects
  - OrganizationMembers
  - OrganizationInvitations
  - OrganizationConfirmations
  - Subscriptions
  - Coupons
  - Credentials
  - Secrets
  - activity
  - Apps
  - Services
  - Deployments
  - Archives
  - RegionalDeployments
  - Instances
  - Domains
  - PersistentVolumes
  - Snapshots
  - Compose
  - Repositories
  - Logs
  - Metrics
  - Catalog
  - CatalogRegions
  - CatalogInstances
  - Usages
  - Summary
  - DockerHelper