Validates the secret name and proxies the upsert request to ECP scoped to a workspace. The project scope is carried by the route id path parameter and the org is derived from that project. Accepts either a session JWT or a project-scoped API key, so CI/CD can seed short-lived build credentials without an interactive login; an API key must be scoped to the project named in the path. The caller needs deployment-management rights on that project (PROJECT_OWNER, AGENT_DEVELOPER, ORG_ADMIN on Agent Engine-native projects, or SYSTEM_ADMIN).
Body
Required
Secret value and optional description
-
ValueUnchanged must be explicitly set by a caller editing only the description of an existing secret; it is what allows Value to be empty. Without it, an empty Value is always rejected - a caller that sends "" by mistake (e.g. a templating bug or unset env var) gets a clear 400 instead of silently leaving the old value in place.
Responses
-
Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence.
-
OK
-
Bad Request
-
Forbidden
-
Not Found
-
Request Entity Too Large
-
Too Many Requests
-
Bad Gateway
-
Service Unavailable
curl \
--request PUT 'https://agentengine.mongodb.com/api/v1/projects/{id}/workspaces/{workspace_id}/secrets/{name}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"description": "string",
"value": "string",
"value_unchanged": true
}'
{
"description": "string",
"value": "string",
"value_unchanged": true
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
"error": 406,
"errorCode": "UNACCEPTABLE_MEDIA_TYPE",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
"error": 406,
"errorCode": "UNSUPPORTED_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{}
{}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}