list_secrets

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/list_secrets, with a bearer credential and the action's payload as the JSON body. It also accepts GET.

Contract description

List the stored secrets: each name, its scope (the account, or one environment of one application), when it was stored and last rotated, and the settings the manifest binds it to. It takes no argument and answers every secret of the account, at every scope. A rotated bound value reaches the container at the next deploy or promote, and at a restart where the running copy already carries the binding. Values are never answered.

Access and action metadata

{
  "name": "list_secrets",
  "resource": "secret",
  "tier": "observe",
  "clients": [
    "bearer",
    "browser_session"
  ],
  "summary": "The custody index: names, scopes, and stamps - never values.",
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "list_secrets",
  "tier": "observe",
  "scenario": "EGW-L0-09",
  "summary": "List the stored secrets: each name, its scope (the account, or one environment of one application), when it was stored and last rotated, and the settings the manifest binds it to. It takes no argument and answers every secret of the account, at every scope. A rotated bound value reaches the container at the next deploy or promote, and at a restart where the running copy already carries the binding. Values are never answered.",
  "owners": [
    "SCRT-03",
    "MAN-14"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","secrets"]
/properties/contract_version Required value: 1
/properties/reference The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call.

Type: string
Pattern: ^[0-9a-f]{10}$
/properties/secrets Type: array
/properties/secrets/items Type: object
Required fields: ["name","scope","created_at"]
/properties/secrets/items/properties/name Type: string
/properties/secrets/items/properties/scope Type: string
/properties/secrets/items/properties/created_at Type: string
/properties/secrets/items/properties/rotated_at Type: ["string","null"]
/properties/secrets/items/properties/application Type: ["string","null"]
/properties/secrets/items/properties/environment The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08).

Type: ["string","null"]
/properties/secrets/items/properties/settings The settings the application's manifest binds to this name, which each deploy and promote of the scope's environment injects into its container, and a restart where the running copy already carries the binding (MAN-14); empty where none does and at the account scope.

Type: array
/properties/secrets/items/properties/settings/items Type: string
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "properties": {}
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "secrets"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "reference": {
        "type": "string",
        "pattern": "^[0-9a-f]{10}$",
        "description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
      },
      "secrets": {
        "type": "array",
        "items": {
          "type": "object",
          "required": [
            "name",
            "scope",
            "created_at"
          ],
          "properties": {
            "name": {
              "type": "string"
            },
            "scope": {
              "type": "string"
            },
            "created_at": {
              "type": "string"
            },
            "rotated_at": {
              "type": [
                "string",
                "null"
              ]
            },
            "application": {
              "type": [
                "string",
                "null"
              ]
            },
            "environment": {
              "type": [
                "string",
                "null"
              ],
              "description": "The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08)."
            },
            "settings": {
              "type": "array",
              "items": {
                "type": "string"
              },
              "description": "The settings the application's manifest binds to this name, which each deploy and promote of the scope's environment injects into its container, and a restart where the running copy already carries the binding (MAN-14); empty where none does and at the account scope."
            }
          }
        }
      },
      "detail": {
        "type": "string"
      }
    }
  }
}

Shared contracts