list_secrets
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/list_secrets, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
List the stored secrets: each name, its scope (the account, or one environment of one application), when it was stored and last rotated, and the settings the manifest binds it to. It takes no argument and answers every secret of the account, at every scope. A rotated bound value reaches the container at the next deploy or promote, and at a restart where the running copy already carries the binding. Values are never answered.
Access and action metadata
{
"name": "list_secrets",
"resource": "secret",
"tier": "observe",
"clients": [
"bearer",
"browser_session"
],
"summary": "The custody index: names, scopes, and stamps - never values.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "list_secrets",
"tier": "observe",
"scenario": "EGW-L0-09",
"summary": "List the stored secrets: each name, its scope (the account, or one environment of one application), when it was stored and last rotated, and the settings the manifest binds it to. It takes no argument and answers every secret of the account, at every scope. A rotated bound value reaches the container at the next deploy or promote, and at a restart where the running copy already carries the binding. Values are never answered.",
"owners": [
"SCRT-03",
"MAN-14"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","secrets"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
Type: array |
| / |
Type: object Required fields: ["name","scope","created_at"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08). Type: ["string","null"] |
| / |
The settings the application's manifest binds to this name, which each deploy and promote of the scope's environment injects into its container, and a restart where the running copy already carries the binding (MAN-14); empty where none does and at the account scope. Type: array |
| / |
Type: string |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"properties": {}
},
"response": {
"type": "object",
"required": [
"contract_version",
"secrets"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"secrets": {
"type": "array",
"items": {
"type": "object",
"required": [
"name",
"scope",
"created_at"
],
"properties": {
"name": {
"type": "string"
},
"scope": {
"type": "string"
},
"created_at": {
"type": "string"
},
"rotated_at": {
"type": [
"string",
"null"
]
},
"application": {
"type": [
"string",
"null"
]
},
"environment": {
"type": [
"string",
"null"
],
"description": "The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08)."
},
"settings": {
"type": "array",
"items": {
"type": "string"
},
"description": "The settings the application's manifest binds to this name, which each deploy and promote of the scope's environment injects into its container, and a restart where the running copy already carries the binding (MAN-14); empty where none does and at the account scope."
}
}
}
},
"detail": {
"type": "string"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md