---
id: workflow-config-set
title: "Set a secret or variable"
description: "Creates a secret or variable, or rotates its value if it already exists at that place. Safe to call repeatedly."
sidebar_label: "Set a secret or variable"
hide_title: true
hide_table_of_contents: true
api: eJztWW1v47gR/isD4oBLUln2LrbYng/94N1mgexhs0GSxV6bS21aHNm8UKSOpOz4DP/3YkhJlmNvkmvRfiiSL5FkcjgvzzwzGq2Z5zPHhjfsq7F3uTJLcJhZ9A64FrDgVvKpQsduEybQZVaWXhrNhuy9Re7RAa83gLHt8oRurPFhgfQOFlxVCDIH6YEri1ysAO+lo2M8+Dn3UCqeYQpXPEfwBjKuFFgs6RChVukv+hfdg+s5xoUgHeA9z7xagdEIJodJyf18AkcccqME2gQm/QnkxoKfIyznRiEYO+Na/s7JhmNScrKszZ7AEclpbo9TOu6rlV7qGXDQvMCo52Pqk8L0v2P0j61IBxZztKgzEik9lDK7C7ppXNYeqkowmp5JCxrvPdhKp43hE1JiEuJCuybR7xPIFZ8BtwiyKCpP/h8GD865npHSWCQgUKEPN4Da21WQYkkA9wjSpyxhpkQbPHMm2JA1avcyo3M5Gzr0LGEWf6vQ+XdGrNhwzTKjPWpPl7wslczC/v6vjiCyZi6bY8Hpyq9KZENmpr9i1siRFgUhj8xiCQseYAmLZhHgSksqeYmORIRlW1HOW6ln7CEsT4N1IVxHk3/ejHr/4L3fx7f1xaD3w/h2PUhevX67+W5ynLQhQQHcNS516fno0+kk4GPBbX1LLsJ7XpSKjv94djkaX3/+6fScbRrdn1SOohiWpnCOC7Rg0VdW0+EzLjUlSBtV6cDbClMSX7tkK39qjEKu9w4gwGLPaLVqsvKIhASoE2wJHG2WwlHOlcPjHcNo+SZhlEtP2/MhJFqTup8qX3GlKDUyVTm5QFhKP+/k2K4L+zwjOT3psXBkZrPu6YNbsmrjB0eTZT5O03QCUpC5d7g6fkSnQBYp24S/4OHKSr9iw5s1myK3aEcVueDmdnNLcHWl0S4C8fVgQP/2Q1tnVpcgUPzYIcAldzUtCnLF87NH+uCx9yEVA8RZspdTuwqNDvByCqcHOXOXCKVA7WUu0QW+qPnWg5ILdClcRbHBIhd4Z9mibkg7VuGh3gX4lChnFUCYPsh/KVjSkECN9IRFZhIjuq5KUV/vkYIUh8CyxViWz8avpz+IV/mAE8SeRyKXW1aQGgTmUkv6yQWS+G69hi5RwGYTXUg/tHxBT3fxfn4xHl2cjX86/fsfyumzhtVTmFB2TqDgd3Vsalhtsz7SuuCZRwEUgdVyjjayyB/PaTiiEirjWd3aCdYYf5zChUWH2sNyjrpTXAJSqJI1tfi/mPhPK9Gt6+mjbK0rpcjTkQYfnv2ZHNwCmhoLbXSvzjI6U6IL8jHPMfNygc+IbhAaKYnrDJ031v01hHlIBvk5Uv8iiTeWsJTaQWkxQxE4j3QgdiFUh5MLIw4ahroqKNXqrNrm1H5fF0oItIQHMa23qjTuJS6rxUGtRkRjS3CbNovfrfaV2nRz/IDKubEF92zISM+elwXSli0VPHNLze+vB68e4+yOMS/E/ELML8T8QswvxPw/IeY3P/+8T8zvlSTcoLXGJpTapaLXo49Xn8//E3omcU/ScygKtBKmRjSvUa7Htei10xBALUojtXc17IbAoeDZXGrste9ZmRFE0hXNSAp0js+QtN/lyXDU0+n16ZDwBDCdpTCResGVFOMwH0i294Eq6EE0YkyDgnE7JKAftPHj3FRaPGDEHQkBv1H/xzn9wpqFFPhwMEP0RkhsyaSJ/Z8Pxf6LxvsSA006tFSqgoseiXtpzVRh8advx/8irnhW7J3nWnAruiA4uvzwHt7+ZfAW6rNAoOdSuSTqGIcH39Jpcrwf9qjHk8OMoAKtgS+XZ024596XbtjvtxMat3Iei1Tgoh+UdtuftPG9QwH+t2QQEGqXPgaDc+OhXe8891XHZCa1xxna7o43gzcbMp1c+pToFkWRm6WAZT6W+dd30695Wc0Guh7M0dlSUzCzJ9RtDXX9TkPRfyA2lI/gmI40bi1f7UWtKXtGQ8iiWJhzLlVl0Q1DWkSqLtGCyXPUgkaCuUQVerBYfg9MzXYx9K22oWOa81i6vsu47scx3rNzuaichzlfUMWJHSHUp6/geyKf7+s0jqlcoJ8bGhuWxgVNg25d39bnU39FWe3CpKWyqgNGXsqUKn2puKeSkWamYDR+aaYzV5TZ0fjujKa1gwTRCWEZ1fawiCX1xYemDH38es1Ia8rOy+1E87Sxvhk2dqd8bXey9VbTKcaepDF5p4fqtlCdAit1broE1XRPtIGcE4E0SF+lgz14vaukEgmU1VRJN09oRJyE9tJMg2s7A+c4S4auT7f5g3omNYbB+gdTWXq74K5pJjH2NqOLs2GcvJ+c/G2bHCcn4U0izNUbccJkVYHauxROqb0FR+CZYmaK8JVAV8UUCUYnJxYXkkw8OUnAGdDGz8NI3IXGGJRxPo1njpTkDpvzKCgCQuFF62jGzaGRBUdK3iFMqLmcHKcwoj6Px+m9Bk5y6IAlzeqpYscRvbdyNiNZRtcnnt5jVjVGWsyMrdv16GdKKHplov9JTUG6rLxLwFQ+XlAslJm5WuLVoe8pJydwh1hSoxZe6riKCxx60tmRNKqd5OItK8W3BeN8wXUHpVfoD36GeQidzrz+5fPN/93nm5oDPd77fuiXQ1tu1bZU3LRk5GI3RYR8m7A5cfbwhq3XU+7wi1WbDT3+rUJLA/Fbor4aUTQPT9gcuUAbGPwOV7HBJlz1rkmHLVPudeebpNkxyjIs/aNrbztl5eLz1TXxeP3dKb5OMcuXNLLgRK7hA1ZIXFoQnq2Z4npWhVrHokxifb5bNB4UiWBVU9/1qqPheh1XXJs71JsNS2pTPN2zze1ms/kXhzVFqA==
sidebar_class_name: "post api-method"
info_path: docs/api/workflows
custom_edit_url: null
---

import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import ParamsDetails from "@theme/ParamsDetails";
import RequestSchema from "@theme/RequestSchema";
import StatusCodes from "@theme/StatusCodes";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";
import Heading from "@theme/Heading";

<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Set a secret or variable"}
>
</Heading>

<MethodEndpoint
  method={"post"}
  path={"/workflows/config"}
  context={"endpoint"}
>
  
</MethodEndpoint>



Creates a secret or variable, or rotates its value if it already exists at that place. Safe to call repeatedly.

- The place is exactly one of `path` (a folder, `/` for the whole organization) or `workflow` (one workflow).
- Writing a name that already exists at that place replaces its value; workflows referencing it pick the new value up on their next run.
- The `name` and the `secret` flag are immutable: to change them, delete the entry and recreate it.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={undefined}
>
  
</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"object","required":["name","value","secret"],"properties":{"name":{"type":"string","description":"Entry name (`^[A-Za-z_][A-Za-z0-9_]{0,127}$`), referenced as `secrets.NAME` or `vars.NAME`.","example":"JIRA_TOKEN"},"value":{"type":"string","description":"The value. Never returned again if `secret` is true."},"secret":{"type":"boolean","description":"Write-only secret (true) or readable variable (false).","example":true},"path":{"type":"string","description":"Folder place. Mutually exclusive with `workflow`.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference (`wf_...` id or key). Mutually exclusive with `path`."}}}}}}}
>
  
</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"The entry already existed; its value was rotated.","content":{"application/json":{"schema":{"title":"ConfigEntry","type":"object","description":"A secret or variable. Exactly one of `path` or `workflow` identifies the place it lives. Secret values are write-only: they are never returned by any read.","required":["id","name","secret","createdAt","updatedAt"],"properties":{"id":{"type":"string","example":"cfg_2b9d1f0a"},"name":{"type":"string","description":"Referenced in definitions as `${{ secrets.NAME }}` or `${{ vars.NAME }}`.","example":"NP_API_KEY"},"secret":{"type":"boolean","description":"Immutable. `true` makes the value write-only and redacted everywhere."},"path":{"type":"string","description":"Folder place (`/` is the organization root). Present when the entry lives on a folder.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference. Present when the entry lives on one workflow."},"value":{"type":"string","nullable":true,"description":"Only returned for non-secret entries."},"effective":{"type":"boolean","description":"Only with `ancestors=true`: whether this row wins precedence for its name."},"mode":{"type":"string","enum":["created","updated"],"description":"Write responses only: whether the entry was created or its value rotated."},"createdBy":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}}}}},"201":{"description":"The entry was created.","content":{"application/json":{"schema":{"title":"ConfigEntry","type":"object","description":"A secret or variable. Exactly one of `path` or `workflow` identifies the place it lives. Secret values are write-only: they are never returned by any read.","required":["id","name","secret","createdAt","updatedAt"],"properties":{"id":{"type":"string","example":"cfg_2b9d1f0a"},"name":{"type":"string","description":"Referenced in definitions as `${{ secrets.NAME }}` or `${{ vars.NAME }}`.","example":"NP_API_KEY"},"secret":{"type":"boolean","description":"Immutable. `true` makes the value write-only and redacted everywhere."},"path":{"type":"string","description":"Folder place (`/` is the organization root). Present when the entry lives on a folder.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference. Present when the entry lives on one workflow."},"value":{"type":"string","nullable":true,"description":"Only returned for non-secret entries."},"effective":{"type":"boolean","description":"Only with `ancestors=true`: whether this row wins precedence for its name."},"mode":{"type":"string","enum":["created","updated"],"description":"Write responses only: whether the entry was created or its value rotated."},"createdBy":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}}}}},"4XX":{"description":"Client error, as plain JSON.","content":{"application/json":{"schema":{"title":"ConfigError","type":"object","description":"The error body secrets-and-variables endpoints return: a machine-readable code plus a message.","properties":{"error":{"type":"string","description":"Machine-readable code, e.g. `invalid_name`, `invalid_place`, `secret_flag_immutable`, `not_found`.","example":"invalid_place"},"message":{"type":"string","example":"Provide exactly one of path or workflow"}}}}}},"5XX":{"description":"Unexpected server error.","content":{"application/problem+json":{"schema":{"title":"Problem","type":"object","description":"The standard error body (RFC 7807 problem details, served as `application/problem+json`).","properties":{"type":{"type":"string","description":"Error type URI, e.g. `https://workflow-system.dev/errors/workflow-not-found`.","example":"https://workflow-system.dev/errors/workflow-not-found"},"title":{"type":"string","example":"Not found"},"status":{"type":"integer","example":404},"detail":{"type":"string","example":"No workflow with id wf_ifWBbWfpug0n exists"},"instance":{"type":"string","example":"/workflows/definitions/wf_ifWBbWfpug0n"},"errors":{"type":"array","description":"Present on validation failures: one entry per offending field.","items":{"type":"object","properties":{"path":{"type":"string","example":"/steps/scan/config"},"message":{"type":"string","example":"must have required property 'code'"}}}}}}}}}}}
>
  
</StatusCodes>


      