---
id: workflow-config-list
title: "List secrets and variables"
description: "Lists the entries defined at a place: a folder (`path`) or a workflow (`workflow`), exactly one of the two. With `ancestors=true`, returns the whole precedence chain up to `/`, flagging each row's `effective` winner. Secret values are never included."
sidebar_label: "List secrets and variables"
hide_title: true
hide_table_of_contents: true
api: eJzlWG1v4zYS/isD4oBNXFlOiy16Z+A+ZLfZQ3q322BfkB62QUSLI4sNRaokZcc1/N+LISVLjh0nzdfmS2SJnBnOPPPMDNfM87lj06/s2ti7QpklOMwtegdcC1hwK/lMoWM3CRPocitrL41mU/Y/6bwDXyKg9laiA4GF1CiAe+BQK57jFDgURgm0cJLV3JfZKRgLHJadspOse8xOE8B7nnu1AqMRTBGE+6VJ4Vr6EjKuc3TeWPdvbxvMErDoG6ujEcvSKITaYo4CdY6Ql1xqaGrwBrJJlkCh+Hwu9RyQ5yVYs3zlIMOiwNzLBWawlFqjTeFTOD8suGrQAbcIGhdoQepcNQJFyhJmarScHHEp2JR1RxjnRhdyPlXSeZawmlteoUdL/l0zSV77vUG7YgnTvEI2ZeQTljCXl1hxNl0zv6rpvfNW6jnbPHT6u+jM4NwU3je+4UqtAO9z1Ti5QFgGT219SrbiPa9qRVInPCc5Y+mxcmyTHLap2/xX7NqCx2KBlvx/xLoAhPRR/dswHzJgZoxCrhkZUPBGeTYtuHK4Z9FljFbARtEoBRadUQ19baERjRkAgADiUra5SZjDvLHSr0LgZsgt2vPGl2z69YY+W3S10Q4dWfbd2Rn921X/uc8LikFutEftaR2vayXzAJ7Jb44Wr/ePaWa/YR4wZAlqXkZVgvvhKm4tJ8fFeNJ76UOg3wYcXmgf/PpQ5q6l523CU2J26Z7CxW4mxpjRkh5bIAVqLwtKffJyACVID0ou0B3Ko6WVHsdGq9WUdqwGyRVTGQXMVsD1CizykGgWf2+kRUEMJUUHkhAgi3SY3CL3KM7pualF+3zz0HNS7KN4mBp5Mb/9bvYv8W1xxgneEYv7O3Z997FDuwCpI/9J+uSAO8j+sV53ZJp+OH9/AZtNdCF9WHDbv91N0w9Xt+dXl7f/vfg/WdKe9HAK7CC+qhofo5cFgoSK37WxCUEY+D+Qu0XBc48CKAKrZYkWKSsjKT159iEVwUk2yUBGXcbOuZZ/BISDNcafpnBl0aH2sCxRb2vGKiIFjN6WieN81VPTk9YdIqSnjCCsdxqCI4LXDunSjVLkaTYlRz/U/TM5eAvowljQRo/bLNuSwiZhW+55RnSD0OWhOjilA/kSLfhSOipsVMrcsBaSDdI7IFQHzZURBw+Guqko1dqs6nNqv/5fE5hgy4QQ07o3pXPvkjtoxUFrRkSjNZ5eBnvaBW9WB2tNn+MHTC6MrbhnUyJHHHtZIW3pqeCZW7q/hL3+5Zd9Pn+rJEEHrTU2oeyuFdWQnz79/OGv8fsuQ5O4Jxk61BJaCTMjVh2ljLkW421/BqhFbaT2rkUetV4Vz0upcUxkSqsgN4J4unH0EZ3jc0z3ikxQ9XSGvT8kPAFM5ylkUi+4kuKWAJcl/e/AFvQiHuKWSu6t7IiLPmjjbwvTaPGAFHckBAhH+4/T+pU1CynwYWNJDEdg3PJJF/vvD8X+i8b7GgNTOrRUrYKLjsS9tmamsPrm8fhfxRXPir3zXAtuxRAEJx/fvYUf/nn2A7S6QKDnUrkk2ihCBXrMpux0P+zRjqeiHhALtAa+fLzswl16X7vpZLJthN3KeaxSgYtJMNr1n7Tx40MBfpEMAkLr0mMw+GA8bNc7z30zODKT2uMc7XDH67PXoaMklz4luh9mAj1LAcviVhbXb2bXRd3MzzTgPc1KpFtqCmb+hLnbg7rJoKeYPBAbKkhwzIGWcDdqXeUzGkIWxdpccKkai24a0iKydY0WTFGgFjQpFRJVaMP6DvNof/pY5zA4mvNYu4nLuZ7EaenZuVw1zkPJF1R0YlMIrfYVvCLyedWzeJDpS0PT2RzjMEamDV3bqqcOi5I6DmmNVQMs8lqmVOtrxT0VjTQ31c588IkSO559OCVsj0GCujEmVPewiCXtw7uuEP10/ZltAj4KM6SJro2hWYhsjOE8S79Nz/aC/KaRSiRQNzMlXZmAbXQS+jwzCyfc4jQ0O1Sgh0frUYx6LjWmv+pf9TvTWGrzueu6OoxNxvnV5ZQWjGE0+rGH6GgUWvowj3fihMmbCrV3KVxQnwmOQjjD3FQ0FoBuqhlSMEcjiwtJRxyNEnAGtPEloVC60KGCMs6nUee5ktxhp4+qjIBQ/tA6Gvg5dLLgRMk7hIy6vOw0hXNquLgnuVwDJzmkYFlyD/E2gToUb+V8TrKMbjVe3GPedIe0mBvb9s3RzwRrml3of9ISga4b7xIwjY8PFAtl5q6V+OnQPctoBHeINXVMYbriKi5w6MlmR9K6q5GeG2LbbpyveKg37SRNVzSPXOc8AM+6r2R/74udNm893vtJaPFCM2lVz25ft1OIiw0AkchNwkrjPH1dr2fc4RerNht6HS83iFqEdOR70d5YHInAS255Dhp+h6v+kqmdZli4eHm+MS+52jlqzuB+6YUmvfxu56hhw4un3rIb+hHTJlz/JKxELtCGmMaN53mOtR/s2psBSMq2IP3n4jNLGN+tFA8qQ5De1XS9Gsher+OKz+YO9WbDOus9/Wabm81m8yfrtqt5
sidebar_class_name: "get api-method"
info_path: docs/api/workflows
custom_edit_url: null
---

import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import ParamsDetails from "@theme/ParamsDetails";
import RequestSchema from "@theme/RequestSchema";
import StatusCodes from "@theme/StatusCodes";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";
import Heading from "@theme/Heading";

<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"List secrets and variables"}
>
</Heading>

<MethodEndpoint
  method={"get"}
  path={"/workflows/config"}
  context={"endpoint"}
>
  
</MethodEndpoint>



Lists the entries defined at a place: a folder (`path`) or a workflow (`workflow`), exactly one of the two. With `ancestors=true`, returns the whole precedence chain up to `/`, flagging each row's `effective` winner. Secret values are never included.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={[{"in":"query","name":"path","schema":{"type":"string"},"description":"Folder place. Mutually exclusive with `workflow`.","example":"/action-items"},{"in":"query","name":"workflow","schema":{"type":"string"},"description":"Workflow reference. Mutually exclusive with `path`."},{"in":"query","name":"ancestors","schema":{"type":"boolean","default":false},"description":"Include the full resolution chain with `effective` flags."}]}
>
  
</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={undefined}
>
  
</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"The entries.","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"array","items":{"title":"ConfigEntry","type":"object","description":"A secret or variable. Exactly one of `path` or `workflow` identifies the place it lives. Secret values are write-only: they are never returned by any read.","required":["id","name","secret","createdAt","updatedAt"],"properties":{"id":{"type":"string","example":"cfg_2b9d1f0a"},"name":{"type":"string","description":"Referenced in definitions as `${{ secrets.NAME }}` or `${{ vars.NAME }}`.","example":"NP_API_KEY"},"secret":{"type":"boolean","description":"Immutable. `true` makes the value write-only and redacted everywhere."},"path":{"type":"string","description":"Folder place (`/` is the organization root). Present when the entry lives on a folder.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference. Present when the entry lives on one workflow."},"value":{"type":"string","nullable":true,"description":"Only returned for non-secret entries."},"effective":{"type":"boolean","description":"Only with `ancestors=true`: whether this row wins precedence for its name."},"mode":{"type":"string","enum":["created","updated"],"description":"Write responses only: whether the entry was created or its value rotated."},"createdBy":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}}}}}}}},"4XX":{"description":"Client error, as plain JSON.","content":{"application/json":{"schema":{"title":"ConfigError","type":"object","description":"The error body secrets-and-variables endpoints return: a machine-readable code plus a message.","properties":{"error":{"type":"string","description":"Machine-readable code, e.g. `invalid_name`, `invalid_place`, `secret_flag_immutable`, `not_found`.","example":"invalid_place"},"message":{"type":"string","example":"Provide exactly one of path or workflow"}}}}}},"5XX":{"description":"Unexpected server error.","content":{"application/problem+json":{"schema":{"title":"Problem","type":"object","description":"The standard error body (RFC 7807 problem details, served as `application/problem+json`).","properties":{"type":{"type":"string","description":"Error type URI, e.g. `https://workflow-system.dev/errors/workflow-not-found`.","example":"https://workflow-system.dev/errors/workflow-not-found"},"title":{"type":"string","example":"Not found"},"status":{"type":"integer","example":404},"detail":{"type":"string","example":"No workflow with id wf_ifWBbWfpug0n exists"},"instance":{"type":"string","example":"/workflows/definitions/wf_ifWBbWfpug0n"},"errors":{"type":"array","description":"Present on validation failures: one entry per offending field.","items":{"type":"object","properties":{"path":{"type":"string","example":"/steps/scan/config"},"message":{"type":"string","example":"must have required property 'code'"}}}}}}}}}}}
>
  
</StatusCodes>


      