List Secret Providers
local, aws_secrets_manager). Board access required.
List Provider Vault Configs
Create Provider Vault Config
List Secrets
Create Secret
managedMode: "external_reference", provider: "aws_secrets_manager", a providerConfigId, and an externalRef. The UI’s import flow creates these rows without reading plaintext values.
Update Secret Metadata
name, description, and externalRef. Does not accept a value field and does not create a new secret version. To rotate the encrypted value, use the rotate route below.
Rotate Secret Value
externalRef is optional (used when the secret is stored in an external provider such as AWS Secrets Manager). Agents referencing "version": "latest" automatically get the new value on next heartbeat.
Delete Secret
{ "ok": true } on success.