List secrets for a workspace
The secrets of a repository (with the workspace's rows that reach it) or of a workspace: each row's key, the environments it applies to, and whether workflows (secrets.NAME), deployments, or both read it.
GET
/workspaces/{workspace}/actions/secretsValues are never returned. A repository’s need the Admin role on it; a workspace’s, a member.
Values are never returned. A repository’s list includes the workspace’s rows that reach it, with scope set to workspace. Empty environments means every environment.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
list_actions_secrets, with the same inputs - Also at:
GET /repos/{owner}/{name}/actions/secrets
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
workspace |
string | Yes | Instead of repo: the workspace, for the ones every repository in it reads. |
Example request
Section titled “Example request”curl https://api.g1t.sh/workspaces/flagon-io/actions/secrets \ -H "Authorization: Bearer $G1T_TOKEN"Example response
Section titled “Example response”A successful request answers 200 with:
[ { "id": "set_01kpv9q4r7s0t3v6w9x2y5z8ab", "name": "NPM_TOKEN", "kind": "secret", "value": null, "scope": "workspace", "updated_at": "2026-10-04T15:42:07.318Z", "available_to": [ "workflows" ], "environments": [], "projects": [], "note": null, "updated_by": "syntaqx" }]Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 422 | invalid |
The input is not valid. message says which field and why. |