For the complete documentation index, see llms.txt.
Skip to main content
Version: 8.10 (unreleased)

List secretsAdded in 8.10

POST 

/secrets/list

Strongly Consistent About endpoint data consistency

List the camunda.secrets.* references known for the caller's physical tenant.

Only references the caller holds SECRET:READ on are returned. This endpoint never returns secret values, only the reference names.

The references are read from the secret stores configured for the caller's physical tenant. A store may hold names outside the reference name charset (for example one containing a dot); those are omitted, since /secrets/resolve would reject them and no permission can be granted on them.

A returned reference is usable verbatim with /secrets/resolve. In a FEEL expression, however, a name that is not a bare identifier has to be backtick-escaped, since FEEL reads a bare dash as the minus operator: a listed camunda.secrets.db-password is written =camunda.secrets.`db-password` in a BPMN input mapping.

Required permissions​

When authorization is enabled, this endpoint requires the following permission. See resources and permissions to learn more.

Resource typePermission
SECRETREAD

Results you are not authorized to access are filtered from the response rather than rejected.

Request​

Responses​

The references the caller is authorized to see.