Skip to main content
PATCH

Authorizations

Authorization
string
header
required

Runpod API key authentication. Generate an API key in the Runpod console and send it in the Authorization header as Bearer <api_key>. Keys are scoped to the permissions granted when created; requests may return 403 when a valid key lacks access to the requested resource or action.

Path Parameters

id
string
required

Secret identifier

Body

application/json

Only the provided fields are updated; at least one field is required. The secret's name is immutable.

value
string

New secret value, replacing the current one. Write-only. Must be smaller than 16 MiB of UTF-8 text (strictly under 16,777,216 bytes).

Required string length: 1 - 16777216
description
string

New human-readable description, at most 65,535 bytes of UTF-8 text. Send "" to clear.

Maximum string length: 65535

Response

OK

An account-scoped secret: an encrypted string stored by Runpod, referenced from pod, serverless, and template environment variables with the {{ RUNPOD_SECRET_<name> }} placeholder, substituted with the secret's value when the pod or worker boots. The value is write-only and never returned by the API.

id
string
required

Unique secret identifier

Example:

"2q9m7x4cavgd"

name
string
required

Unique, human-readable name — the <name> referenced by the RUNPOD_SECRET_<name> placeholder. Immutable after creation.

Example:

"hf-token"

createdAt
string<date-time>
required

When the secret was created

description
string | null

Human-readable description

Example:

"Hugging Face read token"

valueLastUpdatedAt
string<date-time> | null

When the secret's value was last set (creation or rotation)

Last modified on September 17, 2026