Set Secret

Create or replace a workspace or caller-owned personal secret. The value is encrypted at rest, is write-only, and is never included in the response. A workspace API key cannot call this operation and is rejected with 403; use a personal API key.

PUT/api/v2/secrets/{name}
X-API-Key<token>

Your Sim API key, personal or workspace-scoped. Generate one from the Sim dashboard under Settings > API Keys. A workspace API key is not accepted everywhere: operations that act on behalf of a specific human — administrative reads, secret access, and irreversible or governance-affecting writes — always reject it, whatever role the key carries. Each such operation says so in its own description, and the rejection surfaces as 403 unless the operation conceals unauthorized resources, in which case it is reported as 404. Use a personal API key for those.

In: header

Path Parameters

name*string

Secret to create, replace, or delete.

Match^[A-Za-z0-9_]+$
Length1 <= length <= 255

Request Body

application/json

Ownership scope and write-only value for the secret.

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PUT "https://www.sim.ai/api/v2/secrets/string" \  -H "Content-Type: application/json" \  -d '{    "workspaceId": "a91c4b2e-6d3f-4e8a-b5c7-0d9e2f1a8c64",    "scope": "workspace",    "value": "YOUR_SECRET_VALUE"  }'
{
  "data": {
    "name": "STRIPE_API_KEY",
    "scope": "workspace",
    "role": "admin",
    "createdAt": "2026-06-01T09:14:00.000Z",
    "updatedAt": "2026-06-20T14:02:11.000Z"
  }
}
{
  "data": {
    "name": "STRIPE_API_KEY",
    "scope": "workspace",
    "role": "admin",
    "createdAt": "2026-06-01T09:14:00.000Z",
    "updatedAt": "2026-06-20T14:02:11.000Z"
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}
{
  "error": {
    "code": "BAD_REQUEST",
    "message": "The request is invalid."
  }
}