Skip to content
PUT/repos/{owner}/{name}/actions/secrets/{setting}

Without id or environments, the key’s row for every environment, as GitHub’s API addresses a secret. available_to is workflows and/or deployments (both, for a new row); environments limits it to some, such as production or preview, so a key can hold a value per environment. A variable’s row can become a secret this way; a secret never becomes a variable. A repository’s need the Admin role on it; a workspace’s, an owner. Workspace tokens, G1T_TOKEN included, cannot change them.

Keys are uppercased. See secrets and variables.

Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
setting string Yes The key, such as NPM_TOKEN.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
value string No Needed for a new row; left out, the row keeps its value.
id string No The row to change, from a list. Left out: the key’s row for every environment.
available_to array of strings No Who reads it. Both for a new row. One of workflows, deployments.
environments array of strings No The environments it applies to, such as production and preview, or a workflow job’s environment. Empty is every environment.
projects array of strings No A workspace’s row: the projects it reaches, by slug. Empty is every one.
note string No Where to rotate it, or who to ask.
workspace string No Instead of repo: the workspace, for the ones every repository in it reads.
curl -X PUT https://api.g1t.sh/repos/flagon-io/hello/actions/secrets/STRIPE_KEY \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"value": "sk_live_…",
"available_to": [
"workflows",
"deployments"
],
"environments": [
"production"
]
}'

A successful request answers 200 with:

{
"id": "set_01kpv9q4r7s0t3v6w9x2y5z8ac",
"name": "STRIPE_KEY",
"kind": "secret",
"value": null,
"scope": "project",
"updated_at": "2026-10-04T15:42:07.318Z",
"available_to": [
"workflows",
"deployments"
],
"environments": [
"production"
],
"projects": [],
"note": null,
"updated_by": "syntaqx"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.