---
title: "Update Secret"
method: PUT
path: "/api/v1/secrets/{secret_id}"
tags: ["secrets"]
---

# Update Secret

`PUT /api/v1/secrets/{secret_id}`

Updates the attribute on a specific secret using its unique id.

Args:
    secret_id: ID of the secret to get.
    secret_update: the model containing the attributes to update.
    patch_values: Whether to patch the secret values or replace them.

Returns:
    The updated secret object.

## Path parameters

- `secret_id` string, uuid, required

## Query parameters

- `patch_values` boolean, nullable

## Request body

- SecretUpdate — Secret update model.
  - `name` string, nullable
  - `scope` 'workspace' | 'user' — Enum for the scope of a secret.
  - `values` object, nullable

## Response `200`

Successful Response

- SecretResponse — Response model for secrets.
  - `body` SecretResponseBody — Response body for secrets.
    - `created` string, date-time, required
    - `updated` string, date-time, required
    - `user` UserResponse — Response model for user and service accounts. This returns the activation_token that is required for the user-invitation-flow of the frontend. The email is returned optionally as well for use by the analytics on the client-side.
      - `body` UserResponseBody — Response body for users.
        - `created` string, date-time, required
        - `updated` string, date-time, required
        - `active` boolean
        - `activation_token` string, nullable
        - `full_name` string
        - `email_opted_in` boolean, nullable — `null` if not answered, `true` if agreed, `false` if skipped.
        - `is_service_account` boolean, required
        - `is_admin` boolean, required
      - `metadata` UserResponseMetadata — Response metadata for users.
        - `email` string, nullable
        - `external_user_id` string, uuid, nullable
        - `user_metadata` object
      - `resources` UserResponseResources — Class for all resource models associated with the user entity.
      - `id` string, uuid, required
      - `permission_denied` boolean
      - `name` string, required
    - `scope` 'workspace' | 'user' — Enum for the scope of a secret.
    - `values` object
  - `metadata` SecretResponseMetadata — Response metadata for secrets.
    - `workspace` WorkspaceResponse, required — Response model for workspaces.
      - `body` WorkspaceResponseBody — Response body for workspaces.
        - `created` string, date-time, required
        - `updated` string, date-time, required
      - `metadata` WorkspaceResponseMetadata — Response metadata for workspaces.
        - `description` string
      - `resources` WorkspaceResponseResources — Class for all resource models associated with the workspace entity.
      - `id` string, uuid, required
      - `permission_denied` boolean
      - `name` string, required
  - `resources` SecretResponseResources — Class for all resource models associated with the secret entity.
  - `id` string, uuid, required
  - `permission_denied` boolean
  - `name` string, required

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Unprocessable Entity

---

[API](https://skmtc.net/zenml-io/apis/zenml-2.md) · [All operations](https://skmtc.net/zenml-io/apis/zenml-2/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/zenml-io/zenml-2/revisions/febb01b8bce3/schema)
