---
title: "List secrets"
method: GET
path: "/projects/{projectId}/secrets"
tags: ["Secrets"]
---

# List secrets

`GET /projects/{projectId}/secrets`

The project's credentials as METADATA ONLY — no value is returned by this or any other route. Shows the project-shared secrets plus the caller's own personal ones; another member's personal secret does not appear at all, not even its name.

## Response `200`

A page of secrets.

- SecretPage
  - `items` Secret[], required
    - `id` string, required
    - `projectId` string, required
    - `name` string, required — The environment-variable name (`^[A-Z_][A-Z0-9_]*$`). This IS the secret's identity: what a materialized delivery exports, what a workflow references, and what stays stable across a rotation. Immutable.
    - `description` string, nullable, required
    - `delivery` 'brokered' | 'materialized', required — `brokered` — the sandbox's egress proxy injects the value as a request header OUTSIDE the VM, so the box never holds it. Prevents EXTRACTION, not USE: any process in the box can call the bound host while the policy is live, and it works for HTTPS APIs only (domain rules bind on ports 80/443). `materialized` — a real environment variable inside the box, which is the only thing a CLI can read; EXTRACTABLE BY DESIGN.
    - `brokerHosts` string[] — Brokered only: the exact hostnames the header is injected on.
    - `brokerHeader` string — Brokered only: the header name.
    - `brokerTemplate` string — Brokered only: the header value, with `{}` where the secret goes.
    - `sharing` 'user' | 'project', required — `project` — admin-managed, delivered to every member's sessions. `user` — personal, delivered ONLY in sessions its owner starts and silently absent from anyone else's run of the same environment. Immutable.
    - `ownerUserId` string — Personal secrets only. Project-shared rows have no owner.
    - `lastDeliveredAt` integer, nullable, required — When this secret was last HANDED TO a run — not when it was last used. Brokered use is unobservable by construction (the proxy injects the header; the request is never seen here), so `used` would be a number nobody can honestly produce. `null` means nothing has been recorded, which is not the same as never delivered.
    - `createdAt` integer, required
    - `updatedAt` integer, required
    - `createdByUserId` string, required
    - `updatedByUserId` string, required
  - `nextCursor` string — Present only when another page exists. Opaque — do not parse it.

## Other responses

- `401` — Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is a property of the server, not your key.
- `403` — Key is valid but not allowed to do this.
- `404` — Unknown project, server, or resource.
- `429` — Per-key rate limit exceeded (60 requests/minute sustained, bursts up to 10). Honor `Retry-After` and back off with jitter.
- `500` — Something failed on MCPJam's side.

## Changes

- **2026-09-01** `ce6e4188e558` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/mcpjam/apis/mcpjam-api/changes/projects/:projectId/secrets/get.md)

---

[API](https://skmtc.dev/mcpjam/apis/mcpjam-api.md) · [All operations](https://skmtc.dev/mcpjam/apis/mcpjam-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/mcpjam/mcpjam-api/revisions/3d62c6919d8d/schema)
