---
title: "Set a Secret"
method: POST
path: "/v1/apps/secrets"
---

# Set a Secret

`POST /v1/apps/secrets`

Create or replace a secret in the secret store.

## Response `200`

Successful response.

- AppsSecret — Secret Store is an API that allows Stripe Apps developers to securely persist secrets for use by UI Extensions and app backends. The primary resource in Secret Store is a `secret`. Other apps can't view secrets created by an app. Additionally, secrets are scoped to provide further permission control. All Dashboard users and the app backend share `account` scoped secrets. Use the `account` scope for secrets that don't change per-user, like a third-party API key. A `user` scoped secret is accessible by the app backend and one specific Dashboard user. Use the `user` scope for per-user secrets like per-user OAuth tokens, where different users might have different permissions. Related guide: [Store data between page reloads](https://stripe.com/docs/stripe-apps/store-auth-data-custom-objects)
  - `created` integer, required — Time at which the object was created. Measured in seconds since the Unix epoch.
  - `deleted` boolean — If true, indicates that this secret has been deleted
  - `expires_at` integer, nullable — The Unix timestamp for the expiry time of the secret, after which the secret deletes.
  - `id` string, required — Unique identifier for the object.
  - `livemode` boolean, required — Has the value `true` if the object exists in live mode or the value `false` if the object exists in test mode.
  - `name` string, required — A name for the secret that's unique within the scope.
  - `object` 'apps.secret', required — String representing the object's type. Objects of the same type share the same value.
  - `payload` string, nullable — The plaintext secret value to be stored.
  - `scope` SecretServiceResourceScope, required
    - `type` 'account' | 'user', required — The secret scope type.
    - `user` string — The user ID, if type is set to "user"

## Other responses

- `default` — Error response.

## Changes

> 9 revisions in range; 2 not diffed.

- **2025-01-17** `b8a91ebdacb7` — 8 info
  - added the optional property `error/advice_code` to the response with the `default` status
  - added the optional property `error/payment_intent/invoice/anyOf[subschema #2: Invoice]/charge/anyOf[subschema #2: Charge]/outcome/anyOf[subschema #1: ChargeOutcome]/advice_code` to the response with the `default` status
  - added the optional property `error/payment_intent/invoice/anyOf[subschema #2: Invoice]/charge/anyOf[subschema #2: Charge]/payment_method_details/anyOf[subschema #1: payment_method_details]/pay_by_bank` to the response with the `default` status
  - added the optional property `error/payment_intent/invoice/anyOf[subschema #2: Invoice]/charge/anyOf[subschema #2: Charge]/payment_method_details/anyOf[subschema #1: payment_method_details]/paypal/country` to the response with the `default` status
  - …4 more
- …earlier changes not shown

[Full history](https://skmtc.dev/stripe/apis/spec3/changes/v1/apps/secrets/post.md)

---

[API](https://skmtc.dev/stripe/apis/spec3.md) · [All operations](https://skmtc.dev/stripe/apis/spec3/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/stripe/spec3/revisions/b8a91ebdacb7/schema)
