> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get secrets

> **Token scope:** `account` · `org` · `project` — read-only tokens allowed.

The secret seam — decrypt and return the branch's credential bundle, or one compute service's slice of it with ?service=<type>/<name>. Both carry the branch's canonical provider credentials (the .env contract, #323); NEITHER reports what a container receives, which needs an explicit binding. A name several services define is listed in `collisions`, and omitted from the bundle when ?on_collision=withhold. Gated — secrets.read.



## OpenAPI

````yaml /openapi/project.json get /projects/{projectId}/secrets
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/secrets:
    get:
      tags:
        - Secrets
      summary: Get secrets
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        allowed.


        The secret seam — decrypt and return the branch's credential bundle, or
        one compute service's slice of it with ?service=<type>/<name>. Both
        carry the branch's canonical provider credentials (the .env contract,
        #323); NEITHER reports what a container receives, which needs an
        explicit binding. A name several services define is listed in
        `collisions`, and omitted from the bundle when ?on_collision=withhold.
        Gated — secrets.read.
      operationId: getSecrets
      parameters:
        - schema:
            type: string
          in: query
          name: branch
          required: false
          description: Branch name (defaults to the project's default branch)
        - schema:
            minLength: 1
            type: string
          in: query
          name: service
          required: false
          description: >-
            Answer with ONE compute service's slice of this seam, as
            "<type>/<name>": that service's user secrets, the unbound ones, its
            explicit provider bindings, and the branch's canonical provider
            credentials. This is the .env seam NARROWED BY SERVICE, not a
            container inspection — a container receives a provider credential
            only where bound, so this read is deliberately wider than the
            deployed env. Compute only; a managed service is a 400 naming
            /services/:serviceId/credentials.
        - schema:
            anyOf:
              - type: string
                enum:
                  - merge
              - type: string
                enum:
                  - withhold
          in: query
          name: on_collision
          required: false
          description: >-
            How to answer a name several services define. "merge" (the default,
            and today's behaviour) returns whichever row is newest; "withhold"
            omits it. Either way the name is listed in `collisions`.
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  secrets:
                    $ref: '#/components/schemas/SecretsBundle'
                  collisions:
                    type: array
                    items:
                      $ref: '#/components/schemas/SecretCollision'
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApprovalRequired'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    SecretsBundle:
      description: >-
        env-var name → decrypted value (e.g. DATABASE_URL, AWS_ACCESS_KEY_ID,
        ...)
      type: object
      additionalProperties:
        type: string
    SecretCollision:
      type: object
      properties:
        name:
          description: >-
            env-var name more than one service defines, so a flat bundle cannot
            attribute a value to it
          type: string
        services:
          description: >-
            "<type>/<name>" of every service that defines it; a since-removed
            holder appears as its service id
          type: array
          items:
            type: string
      required:
        - name
        - services
    ApprovalRequired:
      type: object
      properties:
        status:
          type: string
          enum:
            - approval_required
        approvalId:
          format: uuid
          type: string
        action:
          description: the gated action, or a comma-joined compound set — prefer `actions`
          type: string
        actions:
          description: every capability this approval covers
          type: array
          items:
            type: string
        message:
          type: string
        url:
          description: the console page where a project admin reviews this request
          type: string
        nextActions:
          type: array
          items:
            $ref: '#/components/schemas/NextAction'
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    NextAction:
      type: object
      properties:
        op:
          description: >-
            Neutral logical action id, e.g. "service.add" — NOT an operationId
            or a CLI/MCP tool name; each client maps it to its own surface.
          type: string
        reason:
          description: Natural-language, human/LLM-facing "why do this now".
          type: string
        args:
          description: >-
            Suggested, flat named arguments; "<placeholder>"s where a value is
            unknown.
          type: object
          additionalProperties: true
        gated:
          description: True if the action passes a governance gate.
          type: boolean
      required:
        - op
        - reason
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````