> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superlog.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a workspace secret

> Stores a workspace secret. Agents see the environment variable `name` with a placeholder value, and Superlog substitutes the real value only in requests to the allowed hosts. The value cannot be read back.



## OpenAPI

````yaml /api-reference/openapi.json post /secrets
openapi: 3.1.0
info:
  description: >-
    Manage a Superlog workspace's automations, runs, tag mode, model access, and
    secrets. Every request acts as the member who created the API key.
  title: Superlog management API
  version: 1.0.0
servers:
  - url: https://superlog.sh/api/v1
security:
  - bearerAuth: []
tags:
  - description: The workspace and its members.
    name: Workspace
  - description: Keys that authenticate the management API and MCP server.
    name: API keys
  - description: Connected integrations and the IDs automations and tag mode use.
    name: Integrations
  - description: Create and change automations.
    name: Automations
  - description: Start, follow, and cancel automation runs.
    name: Runs
  - description: What Superlog can use and change when someone mentions it in Slack.
    name: Tag mode
  - description: Model API keys, subscriptions, and available models.
    name: Models
  - description: Credentials agents can use without seeing them.
    name: Secrets
paths:
  /secrets:
    post:
      tags:
        - Secrets
      summary: Create a workspace secret
      description: >-
        Stores a workspace secret. Agents see the environment variable `name`
        with a placeholder value, and Superlog substitutes the real value only
        in requests to the allowed hosts. The value cannot be read back.
      operationId: create_secret
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 80
                  pattern: ^[A-Z_][A-Z0-9_]*$
                  description: The environment variable name, such as `METRICS_API_KEY`.
                value:
                  type: string
                  minLength: 1
                  maxLength: 65536
                  description: The secret value, up to 64 KB.
                allowedHosts:
                  description: >-
                    1 to 20 hostnames without a scheme, path, or port. A leading
                    `*.` matches subdomains.
                  minItems: 1
                  maxItems: 20
                  type: array
                  items:
                    type: string
                    minLength: 1
                    maxLength: 253
                    pattern: >-
                      ^(?:\*\.)?[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)*$
              required:
                - name
                - value
                - allowedHosts
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: object
                    properties:
                      allowedHosts:
                        type: array
                        items:
                          type: string
                      createdAt:
                        type: string
                        format: date-time
                        description: When the secret was stored.
                      id:
                        type: string
                        format: uuid
                        description: Workspace secret ID.
                      name:
                        type: string
                        description: The environment variable name.
                    required:
                      - allowedHosts
                      - createdAt
                      - id
                      - name
                    additionalProperties: false
                required:
                  - secret
                additionalProperties: false
          description: Created
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: The request is invalid. `issues` lists each invalid field.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: The API key is missing, revoked, or its creator left the workspace.
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            The request conflicts with the current state, such as a name already
            in use.
      security:
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        code:
          description: A stable machine-readable error code, when there is one.
          type: string
        error:
          type: string
          description: What went wrong.
        issues:
          description: Validation problems, one per invalid field.
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
              - path
            additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      description: A workspace API key, created in Superlog under Settings → API keys.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.