Validates the secret name and proxies the upsert request to ECP. Secret values are never returned. The project scope is carried by the route id path parameter and the org is derived from that project. Accepts either a session JWT or a project-scoped API key, so CI/CD can seed short-lived build credentials without an interactive login; an API key must be scoped to the project named in the path. A project secret is shared by every workspace in the project, so writing one requires project-ownership rights: PROJECT_OWNER, ORG_ADMIN on Agent Engine-native projects, or SYSTEM_ADMIN. AGENT_DEVELOPER is not sufficient here — use the workspace-scoped secret endpoint for per-workspace credentials.
Body
Required
Secret value and optional description
-
ValueUnchanged must be explicitly set by a caller editing only the description of an existing secret; it is what allows Value to be empty. Without it, an empty Value is always rejected - a caller that sends "" by mistake (e.g. a templating bug or unset env var) gets a clear 400 instead of silently leaving the old value in place.
Responses
-
Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence.
-
OK
-
Bad Request
-
Forbidden
-
Request Entity Too Large
-
Too Many Requests
-
Bad Gateway
-
Service Unavailable
curl \
--request PUT 'https://agentengine.mongodb.com/api/v1/projects/{id}/secrets/{name}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"description": "string",
"value": "string",
"value_unchanged": true
}'
{
"description": "string",
"value": "string",
"value_unchanged": true
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
"error": 406,
"errorCode": "UNACCEPTABLE_MEDIA_TYPE",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
"error": 406,
"errorCode": "UNSUPPORTED_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"created_at": "string",
"description": "string",
"name": "string",
"updated_at": "string",
"version": 42
}
{
"created_at": "string",
"description": "string",
"name": "string",
"updated_at": "string",
"version": 42
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}