Secrets

List credential injection routes

Requires an owner/admin browser session with recent MFA. Returns metadata only; secret values are never included in responses. Tenant API keys and agent tokens cannot read this inventory. Credential injection routes bind a secret to one tenant agent and an explicit allowlisted upstream host/path/method/header. Broad host, path, method, internal-host, line-break, and unsafe header injection patterns are rejected by the API.

get/secrets/routes

Query parameters

secretIdstring

Response

JSON response

oktrue required

Changes

Changed in 2 of the 9 revisions of this API.3

    • added the required property data/items/injectionConfig to the response with the 200 status

      response-required-property-added

    • added the required property data/items/injectionStrategy to the response with the 200 status

      response-required-property-added

    • endpoint added

      endpoint-added

    This revision also has 6 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog