Skip to main content
GET
Get secrets

Authorizations

Authorization
string
header
required

Session access JWT or an API token (insta_<prefix>_<secret>).

Path Parameters

projectId
string<uuid>
required

Query Parameters

branch
string

Branch name (defaults to the project's default branch)

service
string

Answer with ONE compute service's slice of this seam, as "/": that service's user secrets, the unbound ones, its explicit provider bindings, and the branch's canonical provider credentials. This is the .env seam NARROWED BY SERVICE, not a container inspection — a container receives a provider credential only where bound, so this read is deliberately wider than the deployed env. Compute only; a managed service is a 400 naming /services/:serviceId/credentials.

Minimum string length: 1
on_collision

How to answer a name several services define. "merge" (the default, and today's behaviour) returns whichever row is newest; "withhold" omits it. Either way the name is listed in collisions.

Available options:
merge

Response

Default Response

secrets
object

env-var name → decrypted value (e.g. DATABASE_URL, AWS_ACCESS_KEY_ID, ...)

collisions
object[]