---
title: "List the secrets an intern receives"
method: GET
path: "/vault/interns/{internId}/effective-secrets"
tags: ["Vault"]
---

# List the secrets an intern receives

`GET /vault/interns/{internId}/effective-secrets`

Lists, one entry per name, the secret the intern's outbound requests receive: its own secrets, secrets from an attached vault, and workspace secrets, including ones stored before workspace-scoped storage. Where several vaults hold a name, the entry is the one that wins, in the order intern, attached, workspace. The same resolution decides what outbound requests receive, so this list and the intern's requests agree. `scope` says which vault the entry comes from. Responses carry metadata only, never values. Results are ordered by name and paginated with `limit` and `offset`. Returns 404 when the intern's attached vault is no longer available, since the intern then receives no secrets. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.

## Path parameters

- `internId` string, uuid, required — UUID of an intern in the workspace selected by the API key.

## Query parameters

- `limit` integer — Page size, 1 to 100. Defaults to 100.
- `offset` integer — Number of secrets to skip, 0 to 10000. Defaults to 0.

## Response `200`

One page of the secrets the intern receives.

- VaultEffectiveSecretListResponse — One page of the secrets an intern receives, one entry per name.
  - `data` VaultEffectiveSecret[], required
    - `created_at` string, date-time, required
    - `fingerprint` string, nullable, required
    - `hosts` string[], nullable, required
    - `name` string, required
    - `scope` 'intern' | 'attached' | 'workspace', required — Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault.
  - `has_more` boolean, required — True when more secrets exist beyond this page. Request the next page with `offset` increased by the number of returned entries.

## Other responses

- `400` — Bad Request - The secret name, path, query or JSON body failed validation. The vault returns 400 for a malformed request as well.
- `401` — Unauthorized - Missing or unknown API key. Provisioning keys cannot call vault routes.
- `403` — Forbidden - The key has no usable workspace scope, or the request arrived on a regional hostname.
- `404` — Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.
- `408` — Request Timeout - The route deadline passed before the request completed, or the request body stopped arriving.
- `429` — Too Many Requests - The vault rate limit was reached.
- `500` — Internal Server Error - Scope lookup failed.
- `502` — Bad Gateway - The vault could not be reached or returned an unexpected response.
- `503` — Service Unavailable - Vault writes are disabled for the caller, or the vault is not configured.
- `504` — Gateway Timeout - The vault did not answer in time.

## Changes

- **2026-09-29** `8ff62aabfe68` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openrouterteam/apis/openrouter-api/changes/vault/interns/:internId/effective-secrets/get.md)

---

[API](https://skmtc.dev/openrouterteam/apis/openrouter-api.md) · [All operations](https://skmtc.dev/openrouterteam/apis/openrouter-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openrouterteam/apis/openrouter-api/revisions/adcc51a084d1?raw)
