List Secrets

List workspace and caller-owned personal secret metadata. Only names, scope, role, and timestamps are returned; secret values are never read or returned. The bounded set uses the standard cursor envelope with nextCursor always null; there is no second page to fetch. A workspace API key cannot call this operation and is rejected with 403; use a personal API key.

GET/api/v2/secrets
X-API-Key<token>

Your Sim API key, personal or workspace-scoped. Generate one from the Sim dashboard under Settings > API Keys. A workspace API key is not accepted everywhere: operations that act on behalf of a specific human — administrative reads, secret access, and irreversible or governance-affecting writes — always reject it, whatever role the key carries. Each such operation says so in its own description, and the rejection surfaces as 403 unless the operation conceals unauthorized resources, in which case it is reported as 404. Use a personal API key for those.

In: header

Query Parameters

workspaceId*string

Workspace whose secret metadata should be listed.

Length1 <= length
scope?string

Restrict results to one ownership scope.

Value in"workspace" | "personal"
search?string

Case-insensitive substring match against the secret name.

Length1 <= length <= 200
sortBy?string

Field used to sort the result.

Default"name"
Value in"name" | "createdAt" | "updatedAt"
sortOrder?string

Sort direction.

Default"asc"
Value in"asc" | "desc"

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://www.sim.ai/api/v2/secrets?workspaceId=string"
{
  "data": [
    {
      "name": "STRIPE_API_KEY",
      "scope": "workspace",
      "role": "admin",
      "createdAt": "2026-06-01T09:14:00.000Z",
      "updatedAt": "2026-06-20T14:02:11.000Z"
    }
  ],
  "nextCursor": null
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}