---
title: "GET /api/v1/secret-validation-rules"
method: GET
path: "/api/v1/secret-validation-rules"
tags: ["Secret Validation Rules"]
---

# GET /api/v1/secret-validation-rules

`GET /api/v1/secret-validation-rules`

List every Secret Validation Rule in the specified project, of any type.

## Query parameters

- `projectId` string, required

## Response `200`

Default Response

- object
  - `secretValidationRules` union[], required
    - union
      - object
        - `id` string, uuid, required
        - `name` string, required
        - `description` string, nullable
        - `projectId` string, required
        - `secretPath` string, required
        - `isActive` boolean
        - `createdAt` string, date-time, required
        - `updatedAt` string, date-time, required
        - `environment` object, nullable, required
          - `id` string, uuid, required
          - `name` string, required
          - `slug` string, required
        - `type` 'static-secrets', required
        - `keyConstraints` object — Constraints enforced on the secret key when a secret is created or renamed. Omit to leave keys unconstrained.
          - `minLength` integer — The minimum number of characters the secret key must contain.
          - `maxLength` integer — The maximum number of characters the secret key may contain.
          - `regexPattern` string — A regular expression the secret key must match.
          - `requiredPrefix` string — A string the secret key must start with.
          - `requiredSuffix` string — A string the secret key must end with.
        - `valueConstraints` object — Constraints enforced on the secret value when a secret is created or updated. Omit to leave values unconstrained.
          - `minLength` integer — The minimum number of characters the secret value must contain.
          - `maxLength` integer — The maximum number of characters the secret value may contain.
          - `regexPattern` string — A regular expression the secret value must match.
          - `requiredPrefix` string — A string the secret value must start with.
          - `requiredSuffix` string — A string the secret value must end with.
          - `uniqueAcrossLastVersions` integer — How many of the secret's own previous versions the new value must differ from. Between 1 and 25. Omit to accept a value the secret has held before.
          - `uniqueWithinScope` boolean — Set to true to reject a value that another secret in the rule's scope already holds. Requires blind indexing on the project.
      - object
        - `id` string, uuid, required
        - `name` string, required
        - `description` string, nullable
        - `projectId` string, required
        - `secretPath` string, required
        - `isActive` boolean
        - `createdAt` string, date-time, required
        - `updatedAt` string, date-time, required
        - `environment` object, nullable, required
          - `id` string, uuid, required
          - `name` string, required
          - `slug` string, required
        - `type` 'dynamic-secrets', required
        - `providers` string[], required — The dynamic secret providers this rule applies to. A lease is only constrained when its provider is listed here.
        - `passwordConstraints` object, required — Constraints the generated password must satisfy. These replace any password requirements configured on the resource itself.
          - `minLength` integer — The minimum number of characters the generated password must contain.
          - `maxLength` integer — The maximum number of characters the generated password may contain.
          - `regexPattern` string — A regular expression the generated password must match.
          - `requiredPrefix` string — A string the generated password must start with.
          - `requiredSuffix` string — A string the generated password must end with.
      - object
        - `id` string, uuid, required
        - `name` string, required
        - `description` string, nullable
        - `projectId` string, required
        - `secretPath` string, required
        - `isActive` boolean
        - `createdAt` string, date-time, required
        - `updatedAt` string, date-time, required
        - `environment` object, nullable, required
          - `id` string, uuid, required
          - `name` string, required
          - `slug` string, required
        - `type` 'secret-rotations', required
        - `providers` string[], required — The secret rotation providers this rule applies to. A rotation is only constrained when its provider is listed here.
        - `passwordConstraints` object, required — Constraints the generated password must satisfy. These replace any password requirements configured on the resource itself.
          - `minLength` integer — The minimum number of characters the generated password must contain.
          - `maxLength` integer — The maximum number of characters the generated password may contain.
          - `regexPattern` string — A regular expression the generated password must match.
          - `requiredPrefix` string — A string the generated password must start with.
          - `requiredSuffix` string — A string the generated password must end with.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-19** `f66a96419240` — 1 warning, 2 info
  - removed the optional property `secretValidationRules/items/anyOf[subschema #1: Static Secrets]/valueConstraints/reusePrevention` from the response with the `200` status
  - added the optional property `secretValidationRules/items/anyOf[subschema #1: Static Secrets]/valueConstraints/uniqueAcrossLastVersions` to the response with the `200` status
  - added the optional property `secretValidationRules/items/anyOf[subschema #1: Static Secrets]/valueConstraints/uniqueWithinScope` to the response with the `200` status
- **2026-09-12** `9d13865fec5c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/secret-validation-rules/get.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/1c99090073f3?raw)
