---
title: "POST /api/v1/secret-validation-rules/secret-rotations"
method: POST
path: "/api/v1/secret-validation-rules/secret-rotations"
tags: ["Secret Validation Rules"]
---

# POST /api/v1/secret-validation-rules/secret-rotations

`POST /api/v1/secret-validation-rules/secret-rotations`

Create a Secret Rotations Validation Rule for the specified project.

## Request body

- object
  - `name` string, required — The name of the Secret Rotations Validation Rule to create.
  - `projectId` string, required — The ID of the project to create the Secret Rotations Validation Rule in.
  - `description` string, nullable — An optional description of the Secret Rotations Validation Rule.
  - `environment` string — The slug of the environment to scope this rule to. Omit to enforce the rule in every environment of the project.
  - `secretPath` string, required — The secret path to scope this rule to. Supports glob patterns such as `/apps/**`.
  - `isActive` boolean — Whether the rule is enforced. An inactive rule is kept but ignored.
  - `providers` string[], required — The secret rotation providers this rule applies to. A rotation is only constrained when its provider is listed here.
  - `passwordConstraints` object, required — Constraints the generated password must satisfy. These replace any password requirements configured on the resource itself.
    - `minLength` integer — The minimum number of characters the generated password must contain.
    - `maxLength` integer — The maximum number of characters the generated password may contain.
    - `regexPattern` string — A regular expression the generated password must match.
    - `requiredPrefix` string — A string the generated password must start with.
    - `requiredSuffix` string — A string the generated password must end with.

## Response `201`

Default Response

- object
  - `secretValidationRule` object, required
    - `id` string, uuid, required
    - `name` string, required
    - `description` string, nullable
    - `projectId` string, required
    - `secretPath` string, required
    - `isActive` boolean
    - `createdAt` string, date-time, required
    - `updatedAt` string, date-time, required
    - `environment` object, nullable, required
      - `id` string, uuid, required
      - `name` string, required
      - `slug` string, required
    - `type` 'secret-rotations', required
    - `providers` string[], required — The secret rotation providers this rule applies to. A rotation is only constrained when its provider is listed here.
    - `passwordConstraints` object, required — Constraints the generated password must satisfy. These replace any password requirements configured on the resource itself.
      - `minLength` integer — The minimum number of characters the generated password must contain.
      - `maxLength` integer — The maximum number of characters the generated password may contain.
      - `regexPattern` string — A regular expression the generated password must match.
      - `requiredPrefix` string — A string the generated password must start with.
      - `requiredSuffix` string — A string the generated password must end with.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-12** `9d13865fec5c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/secret-validation-rules/secret-rotations/post.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/1c99090073f3?raw)
