---
title: "POST /api/v1/agent-vault/access-bundles/{accessBundleId}/variables"
method: POST
path: "/api/v1/agent-vault/access-bundles/{accessBundleId}/variables"
tags: ["Agent Vault Access Bundles"]
---

# POST /api/v1/agent-vault/access-bundles/{accessBundleId}/variables

`POST /api/v1/agent-vault/access-bundles/{accessBundleId}/variables`

Create a variable in an Agent Vault access bundle

## Path parameters

- `accessBundleId` string, uuid, required

## Request body

- object
  - `key` string, required — The name services use to refer to the variable, as `{{KEY}}`. Starts with a letter and uses only upper case letters, numbers and underscores.
  - `value` string, required — The value the proxy puts in place of each `{{KEY}}`.
  - `isSecret` boolean — Whether the value is hidden once saved. A secret value is only returned by the value endpoint.

## Response `200`

Default Response

- object
  - `variable` object, required
    - `id` string, uuid, required — The ID of the variable.
    - `accessBundleId` string, uuid, required — The ID of the access bundle.
    - `key` string, required — The name services use to refer to the variable, as `{{KEY}}`. Starts with a letter and uses only upper case letters, numbers and underscores.
    - `isSecret` boolean, required — Whether the value is hidden once saved. A secret value is only returned by the value endpoint.
    - `value` string, nullable, required — The value, for a variable that is not secret. Null for a secret one: read it from the value endpoint.
    - `serviceIds` string[], required — The IDs of the services in the access bundle that use this variable. A variable in use can't be deleted.
    - `createdAt` string, date-time, required — When the variable was added to the access bundle.
    - `updatedAt` string, date-time, required — When the variable was last changed.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-10-01** `8d8e9d059648` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/access-bundles/:accessBundleId/variables/post.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/8d8e9d059648?raw)
