Skip to content

The secrets of a repository (with the workspace's rows that reach it) or of a workspace: each row's key, the environments it applies to, and whether workflows (secrets.NAME), deployments, or both read it.

GET/repos/{owner}/{name}/actions/secrets

Values are never returned. A repository’s need the Admin role on it; a workspace’s, a member.

Values are never returned. A repository’s list includes the workspace’s rows that reach it, with scope set to workspace. Empty environments means every environment.

Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
curl https://api.g1t.sh/repos/flagon-io/hello/actions/secrets \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "set_01kpv9q4r7s0t3v6w9x2y5z8ab",
"name": "NPM_TOKEN",
"kind": "secret",
"value": null,
"scope": "workspace",
"updated_at": "2026-10-01T09:12:44.020Z",
"available_to": [
"workflows"
],
"environments": [],
"projects": [],
"note": null,
"updated_by": "syntaqx"
},
{
"id": "set_01kpv9q4r7s0t3v6w9x2y5z8ac",
"name": "STRIPE_KEY",
"kind": "secret",
"value": null,
"scope": "project",
"updated_at": "2026-10-04T15:42:07.318Z",
"available_to": [
"workflows",
"deployments"
],
"environments": [
"production"
],
"projects": [],
"note": "Rotate in the Stripe dashboard.",
"updated_by": "syntaqx"
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.