---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "List secrets"
description: "`secrets.secrets.list` (GET /v1/{parent}/secrets): Lists secrets in an environment."
type: reference
product: platform
summary: "Lists secrets in an environment."
updated: 2026-09-28
nav: false
---

Lists secrets in an environment.

- **Path** `GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets`
- **Scope** `secrets:read`
- **Effect** `read` — nothing is written.
- **Collection** [secrets](/docs/api/secrets)
- **Query** `page_size`, `page_token`, `filter`, `order_by`
- **Pagination** the answer carries `secrets` and, when there is more, `next_page_token`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The environment to list in. Required. |
| `page_size` | `int32` | At most this many; default 50, clamped to 1000. |
| `page_token` | `string` | `next_page_token` of the previous page. |
| `filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `order_by` | `string` | AIP-132 ordering over filterable fields. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `secrets` | `Secret[]` | The page. |
| `next_page_token` | `string` | The token of the next page; empty on the last page. |

### Secret

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/secrets/{secret}`. |
| `uid` | `string` | `sec_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `SecretSpec` | Desired state. Required. |
| `status` | `SecretStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### SecretSpec

| Field | Type | What it is |
| --- | --- | --- |
| `encryption_key` | `string` | The ENCRYPT Key the values are envelope-encrypted with; unset means the environment's default Key. |
| `rotation_period` | `duration` | How often the value should be rotated; the Secret reports Ready=FALSE with reason `RotationDue` once the latest version is older. |
| `deletion_protection` | `bool` | While true, Delete fails with DELETION_PROTECTED. Default true. |

### SecretStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready, Reconciling, Stalled. Output only. |
| `latest_version` | `string` | The newest enabled version; what a binding without a pinned version delivers. Output only. |
| `rotation_due_time` | `timestamp` | When the latest version should be rotated. Output only. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`PAGE_TOKEN_MISMATCH`](/docs/api/errors/PAGE_TOKEN_MISMATCH) — A page token was reused with different parameters.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"
```

**TypeScript**

```ts
const response = await sylphx.secrets.secrets.list({ parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::secrets::ListSecretsRequest::default();
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.secrets().secrets().list(req).await?;
```

**CLI**

```bash
sylphx secrets secrets list orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "secrets.secrets.list", "args": {"parent":"orgs/acme/projects/shop/envs/production"} }
```
