---
title: "Restores a backed up secret to a vault."
method: POST
path: "/secrets/restore"
---

# Restores a backed up secret to a vault.

`POST /secrets/restore`

Restores a backed up secret, and all its versions, to a vault. This operation requires the secrets/restore permission.

## Query parameters

- `api-version` string, required

## Request body

- SecretRestoreParameters — The secret restore parameters.
  - `value` string, base64url, required — The backup blob associated with a secret bundle.

## Response `200`

The request has succeeded.

- SecretBundle — A secret consisting of a value, id and its attributes.
  - `value` string — The secret value.
  - `id` string — The secret id.
  - `contentType` string — The content type of the secret.
  - `attributes` SecretAttributes — The secret management attributes.
    - `enabled` boolean — Determines whether the object is enabled.
    - `nbf` integer — Not before date in UTC.
    - `exp` integer — Expiry date in UTC.
    - `created` integer — Creation time in UTC.
    - `updated` integer — Last updated time in UTC.
    - `recoverableDays` integer — softDelete data retention days. Value should be >=7 and <=90 when softDelete enabled, otherwise 0.
    - `recoveryLevel` 'Purgeable' | 'Recoverable+Purgeable' | 'Recoverable' | 'Recoverable+ProtectedSubscription' | 'CustomizedRecoverable+Purgeable' | 'CustomizedRecoverable' | 'CustomizedRecoverable+ProtectedSubscription' — Reflects the deletion recovery level currently in effect for secrets in the current vault. If it contains 'Purgeable', the secret can be permanently deleted by a privileged user; otherwise, only the system can purge the secret, at the end of the retention interval.
  - `tags` object — Application specific metadata in the form of key-value pairs.
  - `kid` string — If this is a secret backing a KV certificate, then this field specifies the corresponding key backing the KV certificate.
  - `managed` boolean — True if the secret's lifetime is managed by key vault. If this is a secret backing a certificate, then managed will be true.

## Other responses

- `default` — An unexpected error response.

---

[API](https://skmtc.dev/azure/apis/keyvault-secrets.md) · [All operations](https://skmtc.dev/azure/apis/keyvault-secrets/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/azure/keyvault-secrets/revisions/e4f78a39a766/schema)
