---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Create a secret version"
description: "`secrets.secret_versions.create` (POST /v1/{parent}/secret_versions): Adds a value to a secret as its newest version."
type: reference
product: platform
summary: "Adds a value to a secret as its newest version."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Adds a value to a secret as its newest version. The value is never returned.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions`
- **Scope** `secrets:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [secret_versions](/docs/api/secret_versions)
- **Query** `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The secret to create in. Required. |
| `secret_version` | `SecretVersion` | The secret version to create; only spec and caller-writable metadata are read. Required. |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### SecretVersion

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `…/secrets/{secret}/secret_versions/{secret_version}`; the id is the version number, from 1. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `payload` | `bytes` | The value, at most 64 KiB. Write-only. Required. Never returned again. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `…/secrets/{secret}/secret_versions/{secret_version}`; the id is the version number, from 1. |
| `uid` | `string` | `scv_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `payload` | `bytes` | The value, at most 64 KiB. Write-only. Required. Never returned again. |
| `state` | `SecretVersionState` | The version's lifecycle state. Output only. One of `enabled`, `disabled`, `destroyed`. |
| `destroy_time` | `timestamp` | When the value was destroyed. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.
- [`PLAN_LIMIT_REACHED`](/docs/api/errors/PLAN_LIMIT_REACHED) — The plan's limit is reached.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"payload":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.secrets.secretVersions.create({ parent: 'orgs/acme/projects/shop/envs/production/secrets/secret', secretVersion: { payload: '…' } })
```

**Rust**

```rust
let mut req = sylphx::secrets::CreateSecretVersionRequest::default();
req.parent = "orgs/acme/projects/shop/envs/production/secrets/secret".to_string();
req.secret_version = Some(sylphx::secrets::SecretVersion {
    payload: "…".to_string(),
    ..Default::default()
});
let response = sx.secrets().secret_versions().create(req).await?;
```

**CLI**

```bash
sylphx secrets secret-versions create --parent orgs/acme/projects/shop/envs/production/secrets/secret --payload …
```

**MCP**

```json
{ "method_id": "secrets.secret_versions.create", "args": {"parent":"orgs/acme/projects/shop/envs/production/secrets/secret","secret_version":{"payload":"…"}} }
```
