---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "List secret bindings"
description: "`secrets.secret_bindings.list` (GET /v1/{parent}/secret_bindings): Lists secret bindings in an environment."
type: reference
product: platform
summary: "Lists secret bindings in an environment."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Lists secret bindings in an environment.

- **Path** `GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secret_bindings`
- **Scope** `secrets:read`
- **Effect** `read` — nothing is written.
- **Collection** [secret_bindings](/docs/api/secret_bindings)
- **Query** `page_size`, `page_token`, `filter`, `order_by`
- **Pagination** the answer carries `secret_bindings` and, when there is more, `next_page_token`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The environment to list in. Required. |
| `page_size` | `int32` | At most this many; default 50, clamped to 1000. |
| `page_token` | `string` | `next_page_token` of the previous page. |
| `filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `order_by` | `string` | AIP-132 ordering over filterable fields. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `secret_bindings` | `SecretBinding[]` | The page. |
| `next_page_token` | `string` | The token of the next page; empty on the last page. |

### SecretBinding

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/secret_bindings/{secret_binding}`. |
| `uid` | `string` | `scb_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `SecretBindingSpec` | Desired state. Required. |
| `status` | `SecretBindingStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### SecretBindingSpec

| Field | Type | What it is |
| --- | --- | --- |
| `secret` | `string` | The Secret to deliver, in the same environment. Required. |
| `version` | `string` | A pinned version; unset delivers the Secret's latest enabled version. |
| `workload` | `string` | The name of the Resource that consumes the value, for example a Hosting service. Required. |
| `env_var` | `EnvVarDelivery` | As an environment variable. One of the `delivery` group. |
| `file` | `FileDelivery` | As a file. One of the `delivery` group. |
| `egress` | `EgressInjection` | By egress injection into outgoing requests. One of the `delivery` group. |

### SecretBindingStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready, Reconciling, Stalled. Output only. |
| `resolved_version` | `string` | The version the binding delivers now. Output only. |

### EnvVarDelivery

| Field | Type | What it is |
| --- | --- | --- |
| `variable` | `string` | The variable name, for example `DATABASE_PASSWORD`. Required. |

### FileDelivery

| Field | Type | What it is |
| --- | --- | --- |
| `path` | `string` | The absolute path, for example `/run/secrets/tls.key`. Required. |

### EgressInjection

| Field | Type | What it is |
| --- | --- | --- |
| `hosts` | `string[]` | The hosts the value may be sent to, for example `api.example.com`. Required. |
| `header` | `string` | The request header to set, for example `Authorization`. Required. |
| `header_template` | `string` | The header value, with `{value}` standing for the Secret, for example `Bearer {value}`; default `{value}`. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`PAGE_TOKEN_MISMATCH`](/docs/api/errors/PAGE_TOKEN_MISMATCH) — A page token was reused with different parameters.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secret_bindings" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"
```

**TypeScript**

```ts
const response = await sylphx.secrets.secretBindings.list({ parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::secrets::ListSecretBindingsRequest::default();
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.secrets().secret_bindings().list(req).await?;
```

**CLI**

```bash
sylphx secrets secret-bindings list orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "secrets.secret_bindings.list", "args": {"parent":"orgs/acme/projects/shop/envs/production"} }
```
