# Return One Secret for One Organization MCP Configuration **GET /api/atlas/v2/orgs/{orgId}/mcpConfigs/{mcpConfigId}/secrets/{secretId}** Returns metadata for the specified secret on the ingress service account of an organization-level MCP configuration. The secret value is never returned. ## Role requirements - Organization Read Only ## Servers - https://cloud.mongodb.com: https://cloud.mongodb.com () ## Authentication methods - Service accounts - Digest auth ## Parameters ### Path parameters - **orgId** (string) Unique 24-hexadecimal digit string that identifies the organization that contains your projects. Use the [`/orgs`](#tag/Organizations/operation/listOrganizations) endpoint to retrieve all organizations to which the authenticated user has access. - **mcpConfigId** (string) Unique identifier of the MCP configuration. - **secretId** (string) Unique 24-hexadecimal digit string that identifies the secret. ### Query parameters - **envelope** (boolean) Flag that indicates whether Application wraps the response in an `envelope` JSON object. Some API clients cannot access the HTTP response headers or status code. To remediate this, set envelope=true in the query. Endpoints that return a list of results use the results object as an envelope. Application adds the status parameter to the response body. - **pretty** (boolean) Flag that indicates whether the response body should be in the prettyprint format. ## Responses ### 200 OK #### Headers - **RateLimit-Limit** () The maximum number of requests that a user can make within a specific time window. - **RateLimit-Remaining** () The number of requests remaining in the current rate limit window before the limit is reached. #### Body: application/vnd.atlas.2025-03-12+json (object) - **createdAt** (string(date-time)) The date that the secret was created on. This parameter expresses its value in the ISO 8601 timestamp format in UTC. - **expiresAt** (string(date-time)) The date for the expiration of the secret. This parameter expresses its value in the ISO 8601 timestamp format in UTC. - **id** (string) Unique 24-hexadecimal digit string that identifies the secret. - **lastUsedAt** (string(date-time) | null) The last time the secret was used. This parameter expresses its value in the ISO 8601 timestamp format in UTC. - **maskedSecretValue** (string) The masked Service Account secret. - **secret** (string) The secret for the Service Account. It will be returned only the first time after creation. ### 401 Unauthorized. #### Body: application/json (object) - **badRequestDetail** (object | null) Bad request detail. - **detail** (string | null) Describes the specific conditions or reasons that cause each type of error. - **error** (integer(int32)) HTTP status code returned with this error. - **errorCode** (string) Application error code returned with this error. - **parameters** (array[object]) Parameters used to give more information about the error. - **reason** (string | null) Application error message returned with this error. ### 403 Forbidden. #### Body: application/json (object) - **badRequestDetail** (object | null) Bad request detail. - **detail** (string | null) Describes the specific conditions or reasons that cause each type of error. - **error** (integer(int32)) HTTP status code returned with this error. - **errorCode** (string) Application error code returned with this error. - **parameters** (array[object]) Parameters used to give more information about the error. - **reason** (string | null) Application error message returned with this error. ### 404 Not Found. #### Body: application/json (object) - **badRequestDetail** (object | null) Bad request detail. - **detail** (string | null) Describes the specific conditions or reasons that cause each type of error. - **error** (integer(int32)) HTTP status code returned with this error. - **errorCode** (string) Application error code returned with this error. - **parameters** (array[object]) Parameters used to give more information about the error. - **reason** (string | null) Application error message returned with this error. ### 429 Too Many Requests. #### Headers - **RateLimit-Limit** () The maximum number of requests that a user can make within a specific time window. - **RateLimit-Remaining** () The number of requests remaining in the current rate limit window before the limit is reached. - **Retry-After** () The minimum time you should wait, in seconds, before retrying the API request. This header might be returned for 429 or 503 error responses. #### Body: application/json (object) - **badRequestDetail** (object | null) Bad request detail. - **detail** (string | null) Describes the specific conditions or reasons that cause each type of error. - **error** (integer(int32)) HTTP status code returned with this error. - **errorCode** (string) Application error code returned with this error. - **parameters** (array[object]) Parameters used to give more information about the error. - **reason** (string | null) Application error message returned with this error. ### 500 Internal Server Error. #### Body: application/json (object) - **badRequestDetail** (object | null) Bad request detail. - **detail** (string | null) Describes the specific conditions or reasons that cause each type of error. - **error** (integer(int32)) HTTP status code returned with this error. - **errorCode** (string) Application error code returned with this error. - **parameters** (array[object]) Parameters used to give more information about the error. - **reason** (string | null) Application error message returned with this error. [Powered by Bump.sh](https://bump.sh)