> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open.cx/llms.txt
> Use this file to discover all available pages before exploring further.

> Create the secret or replace the value of the one already using this name. Idempotent — safe to call on every deploy to push the current credential.

# Create or replace a secret



## OpenAPI

````yaml put /secrets
openapi: 3.1.0
info:
  title: OpenCX API
  description: >

    OpenCX is an AI-powered, all-in-one platform for customer support and
    outbound communications.


    Use this API to manage your OpenCX organization's AI agents, actions,
    conversations, contacts, and more.


    To get started, generate a new API key from the dashboard.


    ## Authentication

    All API endpoints require authentication using a Bearer token. You can
    generate an API key from your OpenCX dashboard.


    ## Rate Limiting

    API requests are rate limited to ensure fair usage. The current limits are:

    - 100 requests per minute for standard endpoints

    - 1000 requests per minute for streaming endpoints


    ## Error Handling

    The API uses standard HTTP status codes and returns detailed error messages
    in the response body.
  version: 1.0-beta
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.open.cx
    description: Production
security:
  - bearerAuth: []
paths:
  /secrets:
    put:
      summary: Create or replace a secret
      description: >-
        Create the secret, or replace the value of the one already using this
        name. Idempotent — safe to call on every deploy to push the current
        credential without checking whether it exists. Rotating a secret takes
        effect immediately for every action and workflow referencing it by name;
        nothing needs to be re-pointed. The value is encrypted at rest and is
        never returned.
      operationId: upsertSecret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WriteSecretInputDto'
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecretMetadataDto'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDto'
components:
  schemas:
    WriteSecretInputDto:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: '#/components/schemas/WriteSecretInputDtoInput'
      type: object
      properties:
        name:
          type: string
          minLength: 1
          maxLength: 120
          description: >-
            The reference key actions and workflows use as {{secrets.<name>}}.
            Unique per organization, and immutable — writing the same name
            replaces its value rather than renaming anything.
        value:
          type: string
          minLength: 1
          maxLength: 5000
          description: >-
            The plaintext credential. Encrypted at rest and never returned by
            any endpoint.
      required:
        - name
        - value
    SecretMetadataDto:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: '#/components/schemas/SecretMetadataDto'
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        name:
          type: string
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
      required:
        - id
        - name
        - created_at
        - updated_at
      additionalProperties: false
    ErrorDto:
      type: object
      properties:
        statusCode:
          type: integer
        message:
          type: string
        error:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````