Skip to main content
POST
Create a secret slot

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

authorization
string | null
x-ankra-organisation-id
string | null

Body

application/json

Send value or generate, not both.

label
string
required

The slot's name, unique in the organisation, with no line breaks.

Maximum string length: 120
value
string

The secret value. Leave it out when sending generate.

Minimum string length: 1
hint
string

A note about what the secret is for.

Maximum string length: 240
ttl_seconds
integer

How long the slot lives, in seconds. Leave it out for a slot that does not expire. A generated slot is the exception: it defaults to one day and cannot live longer than a week.

generate
SecretSlotGenerate · object

Have Ankra create a random value that nobody sees.

Response

The new slot

A secret slot without its value, which is never returned.

slot_id
string<uuid>
required
label
string
required

The slot's name, unique in the organisation.

hint
string | null
required

A note about what the secret is for, or null.

created_at
string<date-time>
required
expires_at
string<date-time> | null
required

When the slot expires, or null when it does not.

last_accessed_at
string<date-time> | null
required

When the value was last read, or null.

access_count
integer
required

How many times the value has been read.

sentinel
string
required

${SECRET_SLOT:<slot_id>}: put this where the value belongs.

created_via
enum<string>
required

user when a person supplied the current value, generated when Ankra created it.

Available options:
user,
generated
pinned_at
string<date-time> | null
required

When the slot was pinned so it does not expire, or null.

references
SecretSlotReference · object[]
required

The live resources that carry the sentinel.

created_by_user_id
string | null
required

The user who created the slot, or null when unknown.