---
id: workflow-config-set
title: Set a secret or variable
description: >-
  Creates a secret or variable, or rotates its value if it already exists at
  that place. Safe to call repeatedly.
sidebar_label: Set a secret or variable
hide_title: true
hide_table_of_contents: true
api: >-
  eJztWW1v4zYS/isDokATnCx7F1ts66IfvIsskC02GyRZpHepa9HiyGYjkSpJ2VEN/fdiqBfLsTdO73D34ZB8iSRTw3l5nmfo8YY5vrBsfMdutblPUr0Gi7FBZ4ErAStuJJ+naNk0YAJtbGTupFZszN4b5A4t8OYF0KZbHtCN0c4vkM7CiqcFgkxAOuCpQS5KwAdpaRsHbskd5CmPMYRrniA4DTFPUzCY0yYiLcNf1a9qADdLrBeCtIAPPHZpCVoh6ASinLtlBCccEp0KNAFEwwgSbcAtEdZLnSJos+BK/skphlNyMlo3YUdwQnba29OQtrs10km1AA6KZ1j7+ZT75DD97wX9Y2fSgsEEDaqYTEoHuYzvvW8K102Gihy0omfSgMIHB6ZQYRt4RE5Evi70VlTnPYIk5QvgBkFmWeEo/2OfwSVXC3IaswAEpuj8DaBypvRWDBngDkG6kAVM52h8Zs4FG7PW7UGsVSIXY4uOBczgHwVa906Lko03LNbKoXJ0yfM8lbF/f/i7JYhsmI2XmHG6cmWObMz0/HeMWzvSoCDkUVgsYD4DLGB1WAS43JBLTqIlE37Z1pR1RqoFewzLMx+dL9dJ9NvdZPAvPvhzNm0uRoMfZtPNKHj1+m31TXQadCVBAdy2KbXhxeTTWeTxseKmuaUU4QPP8pS2/3h+NZndfP757IJVre9HnaMq+qUhXOAKDRh0hVG0+YJLRQTpqiotOFNgSOablGztz7VOkau9DQiwONAqLVtWnpARD3WCLYGjYymcJDy1eLoTGC2vAkZcOh7PB0+0lrqfClfwNCVqxGlh5QphLd2yx7HdFA55THYG0mFmKcx23fGNO7Hq6gcn0TqZhWEYgRQU7j2Wp0/45MUiZJX/8xkujHQlG99t2By5QTMpKAV302pKcLW5VrYG4uvRiP7tl7ZhVl8gUPzYE8A1t40sCkrF89kjnc/Ye09FD3EW7HFq16HJAV0O4eygZu4KoRSonEwkWq8Xjd46SOUKbQjXtVkfkfW6s+5QN6Y3Sv9Q7QJ8TpJTehCGj/gvBQtaEWiQHrBamcSErotcNNd7oiDFIbBsMRYni9nr+Q/iVTLiBLHnicjVVhWkAoGJVJI+sl4kvtlsoC8UUFV1CumDTi/o6S7eLy5nk8vz2c9n//xbnD5vVT2EiNgZQcbvm9o0sNqyvpZ1wWOHAqgC5XqJplaRv89pOKEWKuu9+r0TjNbuNIRLgxaVg/USVa+5eKRQJ2t78X+R+Med6Pf18Em1VkWaUqZrGXy892dKcAdoOlgorQYNy2hPidbbxyTB2MkVPqO63mgtSVzFaJ029idf5jEF5JZI5xdJurGGtVQWcoMxCq955AOpC6Ha75xpcTAwVEVGVGtYteXU/rnOtxDoBA9qWm9dadNLWtaYg8aNGo2dwFUdi9+V+05VfY4fcDnRJuOOjRn5OXAyQ3plKwXPfKXR99ejV09pdi+YF2F+EeYXYX4R5hdh/p8I85tfftkX5vepJNygMdoERO08pa9HH68/X/wn8kzmjsqzbwq0EuZatF+j7IArMeimIYBK5FoqZxvYjYFDxuOlVDjovmfFWpBIFzQjydBavkDyflcn/VbH6fXpkPEAMFyEEEm14qkUMz8fCLb3XiroQR3EjAYFs25IQB8o7WaJLpR4pIg7Fjx+a/+f1vRLo1dS4OPBDMkbIbETk7b23x2q/ReFDzl6mbRoqFX5FD1R99zoeYrZP75e/8t6xbNqbx1XghvRB8HJ1Yf38Pb70Vto9gKBjsvUBrWP9fDgaz5Fp/tlr/04OszwLtAa+HJ13pZ76Vxux8NhN6GxpXWYhQJXQ++03X6ktBscKvC/ZYOA0KT0KRhcaAfdeuu4K3ohM6kcLtD033gzelNR6JTSY6Y7FNXaLAWsk5lMbt/Nb5O8WIxUM5ijvaWiYsZH3O0CtcPegWL4yKxvHz4xPWvcGF7uVa1te1qBZ1HdmBMu08KgHXta1FKdowGdJKgEjQQTiak/g9Xt98DUbBdDXzs29EKzDnM7tDFXw3qM92wuZ4V1sOQr6jj1iRCa3Uv4lsTn24bGNZUzdEtNY8NcW++p962f22Z/Ol8Rq62ftBQm7YGR5zKkTp+n3FHLCGOdMRq/tNOZa2J2HXx/RtPFQYZoB7+MertfxILm4kPbhj7e3jDymth5tZ1onrXRt8PG/pSvO51ss9WeFOszSRvyzhmqf4TqNVipEk3bUCJq0LwKR+GIdfxiF708wOTy3J8TtXUZVz3/rtEdHMA/xmRvUvsyuP+/G9w36Hf44Ib+pOQPZCbdisRdB0Nb91Gi4jRgS2Lr+I5tNnNu8YtJq4oe/1GgoVHolEDfIIomoQFbIhdoPHfvsayPVoSrwQ35sOXI3rmsCto3JnGMuXty7bQnKJefr2+Iwc0vDvVBmhm+pi+rnGjlf7rwok0L/LMNS7laFF7lWG2T+M535eKRPPioWmVXZc/DzaZecaPvUVUVC5pQHN2zalpV1V9tV4zV
sidebar_class_name: post api-method
info_path: docs/api/nullplatform-api
custom_edit_url: null
canonical: 'https://docs.nullplatform.com/docs/api/workflow-config-set'
---
<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Set a secret or variable"}
>
</Heading>

<MethodEndpoint
  method={"post"}
  path={"/workflows/config"}
  context={"endpoint"}
>

</MethodEndpoint>

Creates a secret or variable, or rotates its value if it already exists at that place. Safe to call repeatedly.

- The place is exactly one of `path` (a folder, `/` for the whole organization) or `workflow` (one workflow).
- Writing a name that already exists at that place replaces its value; workflows referencing it pick the new value up on their next run.
- The `name` and the `secret` flag are immutable: to change them, delete the entry and recreate it.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={undefined}
>

</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"object","required":["name","value","secret"],"properties":{"name":{"type":"string","description":"Entry name (`^[A-Za-z_][A-Za-z0-9_]{0,127}$`), referenced as `secrets.NAME` or `vars.NAME`.","example":"JIRA_TOKEN"},"value":{"type":"string","description":"The value. Never returned again if `secret` is true."},"secret":{"type":"boolean","description":"Write-only secret (true) or readable variable (false).","example":true},"path":{"type":"string","description":"Folder place. Mutually exclusive with `workflow`.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference (`wf_...` id or key). Mutually exclusive with `path`."}}}}}}}
>

</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"The entry already existed; its value was rotated.","content":{"application/json":{"schema":{"title":"ConfigEntry","type":"object","description":"A secret or variable. Exactly one of `path` or `workflow` identifies the place it lives. Secret values are write-only: they are never returned by any read.","required":["id","name","secret","createdAt","updatedAt"],"properties":{"id":{"type":"string","example":"cfg_2b9d1f0a"},"name":{"type":"string","description":"Referenced in definitions as `${{ secrets.NAME }}` or `${{ vars.NAME }}`.","example":"NP_API_KEY"},"secret":{"type":"boolean","description":"Immutable. `true` makes the value write-only and redacted everywhere."},"path":{"type":"string","description":"Folder place (`/` is the organization root). Present when the entry lives on a folder.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference. Present when the entry lives on one workflow."},"value":{"type":"string","nullable":true,"description":"Only returned for non-secret entries."},"effective":{"type":"boolean","description":"Only with `ancestors=true`: whether this row wins precedence for its name."},"mode":{"type":"string","enum":["created","updated"],"description":"Write responses only: whether the entry was created or its value rotated."},"createdBy":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}}}}},"201":{"description":"The entry was created.","content":{"application/json":{"schema":{"title":"ConfigEntry","type":"object","description":"A secret or variable. Exactly one of `path` or `workflow` identifies the place it lives. Secret values are write-only: they are never returned by any read.","required":["id","name","secret","createdAt","updatedAt"],"properties":{"id":{"type":"string","example":"cfg_2b9d1f0a"},"name":{"type":"string","description":"Referenced in definitions as `${{ secrets.NAME }}` or `${{ vars.NAME }}`.","example":"NP_API_KEY"},"secret":{"type":"boolean","description":"Immutable. `true` makes the value write-only and redacted everywhere."},"path":{"type":"string","description":"Folder place (`/` is the organization root). Present when the entry lives on a folder.","example":"/action-items"},"workflow":{"type":"string","description":"Workflow reference. Present when the entry lives on one workflow."},"value":{"type":"string","nullable":true,"description":"Only returned for non-secret entries."},"effective":{"type":"boolean","description":"Only with `ancestors=true`: whether this row wins precedence for its name."},"mode":{"type":"string","enum":["created","updated"],"description":"Write responses only: whether the entry was created or its value rotated."},"createdBy":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}}}}},"4XX":{"description":"Client error, as plain JSON.","content":{"application/json":{"schema":{"title":"ConfigError","type":"object","description":"The error body secrets-and-variables endpoints return: a machine-readable code plus a message.","properties":{"error":{"type":"string","description":"Machine-readable code, e.g. `invalid_name`, `invalid_place`, `secret_flag_immutable`, `not_found`.","example":"invalid_place"},"message":{"type":"string","example":"Provide exactly one of path or workflow"}}}}}},"5XX":{"description":"Unexpected server error.","content":{"application/problem+json":{"schema":{"title":"Problem","type":"object","description":"The standard error body (RFC 7807 problem details, served as `application/problem+json`).","properties":{"type":{"type":"string","description":"Error type URI, e.g. `https://workflow-system.dev/errors/workflow-not-found`.","example":"https://workflow-system.dev/errors/workflow-not-found"},"title":{"type":"string","example":"Not found"},"status":{"type":"integer","example":404},"detail":{"type":"string","example":"No workflow with id wf_ifWBbWfpug0n exists"},"instance":{"type":"string","example":"/workflows/definitions/wf_ifWBbWfpug0n"},"errors":{"type":"array","description":"Present on validation failures: one entry per offending field.","items":{"type":"object","properties":{"path":{"type":"string","example":"/steps/scan/config"},"message":{"type":"string","example":"must have required property 'code'"}}}}}}}}}}}
>

</StatusCodes>

