Project Secret APIs
Write credentials and inspect their metadata and known references. There is no public endpoint to retrieve a stored secret value. Backend consumers resolve bindings when they use a credential.
Use an authorized backend sk_… key in X-API-Key; these configuration operations do not need an end-user identity. A console JWT belongs to the separate console surface. See Authentication.
Tenant context comes from the authenticated request. Client-supplied X-Tenant-Id, X-User-Id or X-Project-Id do not grant authority. The current public integration uses the default project. Do not rely on project headers for separate project, test/live or customer isolation on this API.
This API lacks complete per-action secret permissions. Restrict access to the key-management and secrets-management surfaces. Public write-only behavior does not prove that values are absent from internal storage, journals or diagnostics. A failed write can leave the credential and its metadata inconsistent. Stop using the affected binding and ask your Travila operator to resolve its state before retrying; metadata alone cannot confirm which value is stored.
Related guide: Store and rotate credentials
JSON conventions
Requests accept snake_case or camelCase field names; responses use camelCase. Ordinary default-valued scalars and empty repeated fields can be omitted. Explicitly present optional scalars, map values and well-known JSON types follow their own presence rules: an explicit false, 0 or empty value is not universally equivalent to absence. Decode each field according to its schema. 64-bit integers use JSON strings; preserve their precision. Unknown request fields are generally discarded before validation, so a typo can silently change behavior. This is not a guarantee that arbitrary fields or future client contracts are supported. See API conventions.
Authentication
- API Key: apiKeyAuth
Authorized tenant backend secret key (sk_…). No end-user identity is needed for these tenant/project configuration operations. Keep the key out of client apps; authorization and provisioning still apply.
Security Scheme Type: | apiKey |
|---|---|
Header parameter name: | X-API-Key |
📄️ Overview
Write credentials and inspect their metadata and known references. There is no public endpoint to retrieve a stored secret value. Backend consumers resolve bindings when they use a credential.
📄️ Secret values and credential references
overview}
🗃️ Endpoints
4 items
🗃️ Models
2 items
Document ID: DOC-CP-secrets-api-overview. Section identities and revisions.
| Section | Stable reference |
|---|---|
| Overview | DOC-CP-secrets-api-overview#overview |
| JSON conventions | DOC-CP-secrets-api-overview#json-conventions |
| Authentication | DOC-CP-secrets-api-overview#authentication |
| Scoping | DOC-CP-secrets-api-overview#scoping |
| Rotation | DOC-CP-secrets-api-overview#rotation |