API reference

Environment variables

Read and change a Serverless App Service's environment variables.

Values are encrypted at rest; sensitive values are never returned. See Environment variables for targets and the names the platform reserves.

GET /v1/orgs/:orgId/projects/:projectId/env

Lists the Serverless App Service's variables, and shared: the organization's shared variables (a Serverless App Service variable with the same key replaces a shared one per environment). Values of sensitive variables are null.

Auth: user access token or platform agent key · Scope: env:read

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).

Response 200

{
  vars: {
    version: number
    access: null | {
      roles?: string[]
      teams?: string[]
    }
    rotateEveryDays: null | number
    rotationDueAt: null | number
    value: null | string
    key: string
    createdAt?: number
    updatedAt?: number
    orgId: string
    projectId: string
    targets: ("preview" | "production" | "development")[]
    sensitive?: boolean
    devReadable?: boolean
    updatedBy: string
    valueUpdatedAt?: number
  }[]
  shared: {
    version: number
    access: null | {
      roles?: string[]
      teams?: string[]
    }
    rotateEveryDays: null | number
    rotationDueAt: null | number
    value: null | string
    key: string
    createdAt?: number
    updatedAt?: number
    orgId: string
    projectId: string
    targets: ("preview" | "production" | "development")[]
    sensitive?: boolean
    devReadable?: boolean
    updatedBy: string
    valueUpdatedAt?: number
  }[]
}

Errors

StatusMessage
404Serverless App Service not found

GET /v1/orgs/:orgId/projects/:projectId/env/values

One environment's variables as a deployment gets them (shared ones overridden by the Serverless App Service's), for local development (si env pull, si dev). Sensitive values are null, except development-only secrets marked devReadable when the caller has env:write (audited as env.reveal).

Auth: user access token or platform agent key · Scope: env:read · Allowed: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
Query parameterTypeRequiredDefaultNotes
environment"production" | "preview" | "development"No"development"

Response 200

{
  environment: "preview" | "production" | "development"
  vars: {
    key: string
    value: null | string
    sensitive: boolean
    devReadable?: true
    shared?: true
  }[]
}

Errors

StatusMessage
404Serverless App Service not found

POST /v1/orgs/:orgId/projects/:projectId/env

Creates or replaces many variables at once (e.g. a pasted .env file), all with the same environments and sensitivity. Nothing is written unless every key is valid.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).

Request body

FieldTypeRequiredDefaultNotes
varsobject[]Yes1–200 items
vars[].keystringYes1–256 characters
vars[].valuestringYesup to 65,536 characters
targets("production" | "preview" | "development")[]Yesat least 1 item
sensitivebooleanNotrue
devReadablebooleanNofalse

Response 200

{
  keys: string[]
  targets: ("preview" | "production" | "development")[]
  sensitive: boolean
  devReadable: boolean
}

Errors

StatusMessage
400Invalid names: …. Use letters, numbers and underscores, not starting with a number.
400Reserved by the platform: ….
400Only sensitive variables for Development alone can be readable by developers.
404Serverless App Service not found
429Your plan allows … secrets. Remove some you no longer need, or change plans.
503Some variables weren't saved. Try again.

PUT /v1/orgs/:orgId/projects/:projectId/env/:key

Creates or replaces a variable. Omit value to keep the stored value, for example to change the targets of a sensitive variable.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Request body

FieldTypeRequiredDefaultNotes
valuestringNoup to 65,536 characters
targets("production" | "preview" | "development")[]Yesat least 1 item
sensitivebooleanNotrue
devReadablebooleanNofalse

Response 200

{
  key: string
  targets: ("preview" | "production" | "development")[]
  sensitive: boolean
  devReadable: boolean
  version: number
}

Errors

StatusMessage
400Use letters, numbers and underscores, not starting with a number.
400… is reserved by the platform.
400Only sensitive variables for Development alone can be readable by developers.
400Enter a value.
400Enter a new value to make this variable visible.
400Enter a new value to make this secret readable by developers.
404Serverless App Service not found
429Your plan allows … secrets. Remove some you no longer need, or change plans.

DELETE /v1/orgs/:orgId/projects/:projectId/env/:key

Deletes a variable. Running deployments keep the value they started with.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Response 204 with no body.

Errors

StatusMessage
404Serverless App Service not found

GET /v1/orgs/:orgId/projects/:projectId/env/:key/value

Reads a value back (version: an earlier one). Sensitive values only as their access rule allows; audited.

Auth: user access token or platform agent key · Scope: env:read · Allowed: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.
Query parameterTypeRequiredNotes
versionintegerNo≥ 1; coerced from a string

Errors

StatusMessage
403This secret's access rule doesn't include you. Owners and admins can change who may read it.
403Earlier versions of this secret follow its access rule, which doesn't include you.
404Variable not found
404That version isn't kept any more.

GET /v1/orgs/:orgId/projects/:projectId/env/:key/versions

The versions kept (when each was set and by whom), newest first.

Auth: user access token or platform agent key · Scope: env:read

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Response 200

{
  key: string
  current: number
  versions: {
    version: number
    createdAt?: number
    createdBy: string
    current: boolean
  }[]
}

Errors

StatusMessage
404Variable not found

POST /v1/orgs/:orgId/projects/:projectId/env/:key/versions/:version/restore

Sets an earlier value again, as a new version. Takes effect on the next deployment.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.
:versionA published journey version's number (1, 2, …).

Response 200

{
  key: string
  version: number
}

Errors

StatusMessage
404Variable not found
404That version isn't kept any more.

PUT /v1/orgs/:orgId/projects/:projectId/env/:key/settings

A rotation reminder and who may read the value back.

Auth: user access token or platform agent key · Scopes: env:write, keys:write (when body.access !== undefined)

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Request body

FieldTypeRequiredDefaultNotes
rotateEveryDaysintegerNo1–3650; can be null
accessobjectNocan be null
access.roles[]No[]up to 4 items
access.teamsstring[]No[]up to 50 items; each 1–64 characters

Response 200

{
  key: string
  rotateEveryDays: null | number
  access: null | {
    roles?: string[]
    teams?: string[]
  }
}

Errors

StatusMessage
404Variable not found

GET /v1/orgs/:orgId/env

Lists the organization's shared variables. Sensitive values are null.

Auth: user access token or platform agent key · Scope: env:read

Path parameterDescription
:orgIdOrganization id (org_…).

Response 200

{
  vars: {
    version: number
    access: null | {
      roles?: string[]
      teams?: string[]
    }
    rotateEveryDays: null | number
    rotationDueAt: null | number
    value: null | string
    key: string
    createdAt?: number
    updatedAt?: number
    orgId: string
    projectId: string
    targets: ("preview" | "production" | "development")[]
    sensitive?: boolean
    devReadable?: boolean
    updatedBy: string
    valueUpdatedAt?: number
  }[]
}

POST /v1/orgs/:orgId/env

Creates or replaces many shared variables at once, all with the same environments and sensitivity.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).

Request body

FieldTypeRequiredDefaultNotes
varsobject[]Yes1–200 items
vars[].keystringYes1–256 characters
vars[].valuestringYesup to 65,536 characters
targets("production" | "preview" | "development")[]Yesat least 1 item
sensitivebooleanNotrue
devReadablebooleanNofalse

Response 200

{
  keys: string[]
  targets: ("preview" | "production" | "development")[]
  sensitive: boolean
  devReadable: boolean
}

Errors

StatusMessage
400Invalid names: …. Use letters, numbers and underscores, not starting with a number.
400Reserved by the platform: ….
400Only sensitive variables for Development alone can be readable by developers.
429Your plan allows … secrets. Remove some you no longer need, or change plans.
503Some variables weren't saved. Try again.

PUT /v1/orgs/:orgId/env/:key

Creates or replaces a shared variable. Omit value to keep the stored one.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Request body

FieldTypeRequiredDefaultNotes
valuestringNoup to 65,536 characters
targets("production" | "preview" | "development")[]Yesat least 1 item
sensitivebooleanNotrue
devReadablebooleanNofalse

Response 200

{
  key: string
  targets: ("preview" | "production" | "development")[]
  sensitive: boolean
  devReadable: boolean
  version: number
}

Errors

StatusMessage
400Use letters, numbers and underscores, not starting with a number.
400… is reserved by the platform.
400Only sensitive variables for Development alone can be readable by developers.
400Enter a value.
400Enter a new value to make this variable visible.
400Enter a new value to make this secret readable by developers.
429Your plan allows … secrets. Remove some you no longer need, or change plans.

DELETE /v1/orgs/:orgId/env/:key

Deletes a shared variable. Serverless App Services' own variables with the same key are unaffected.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Response 204 with no body.

GET /v1/orgs/:orgId/env/:key/value

Reads a value back (version: an earlier one). Sensitive values only as their access rule allows; audited.

Auth: user access token or platform agent key · Scope: env:read · Allowed: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.
Query parameterTypeRequiredNotes
versionintegerNo≥ 1; coerced from a string

Errors

StatusMessage
403This secret's access rule doesn't include you. Owners and admins can change who may read it.
403Earlier versions of this secret follow its access rule, which doesn't include you.
404Variable not found
404That version isn't kept any more.

GET /v1/orgs/:orgId/env/:key/versions

The versions kept (when each was set and by whom), newest first.

Auth: user access token or platform agent key · Scope: env:read

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Response 200

{
  key: string
  current: number
  versions: {
    version: number
    createdAt?: number
    createdBy: string
    current: boolean
  }[]
}

Errors

StatusMessage
404Variable not found

POST /v1/orgs/:orgId/env/:key/versions/:version/restore

Sets an earlier value again, as a new version. Takes effect on the next deployment.

Auth: user access token or platform agent key · Scope: env:write

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.
:versionA published journey version's number (1, 2, …).

Response 200

{
  key: string
  version: number
}

Errors

StatusMessage
404Variable not found
404That version isn't kept any more.

PUT /v1/orgs/:orgId/env/:key/settings

A rotation reminder and who may read the value back.

Auth: user access token or platform agent key · Scopes: env:write, keys:write (when body.access !== undefined)

Path parameterDescription
:orgIdOrganization id (org_…).
:keyVariable name; under marketing journeys a person's key: their email address, mobile (E.164) or rec:<record id>, URL-encoded.

Request body

FieldTypeRequiredDefaultNotes
rotateEveryDaysintegerNo1–3650; can be null
accessobjectNocan be null
access.roles[]No[]up to 4 items
access.teamsstring[]No[]up to 50 items; each 1–64 characters

Response 200

{
  key: string
  rotateEveryDays: null | number
  access: null | {
    roles?: string[]
    teams?: string[]
  }
}

Errors

StatusMessage
404Variable not found

GET /v1/orgs/:orgId/secrets

Every secret in the organization (shared ones and each Serverless App Service's sensitive variables): key, targets, current version, last change and by whom, rotation reminder and when it's due, and the access rule. Never values. Also limit, the plan's secretsMax. Needs env:read.

Auth: user access token or platform agent key · Scope: env:read

Path parameterDescription
:orgIdOrganization id (org_…).

Response 200

{
  secrets: {
    project: null | {
      projectId: string
      name: string
    }
    shared: boolean
    version: number
    access: null | {
      roles?: string[]
      teams?: string[]
    }
    rotateEveryDays: null | number
    rotationDueAt: null | number
    value: null | string
    key: string
    createdAt?: number
    updatedAt?: number
    orgId: string
    projectId: string
    targets: ("preview" | "production" | "development")[]
    sensitive?: boolean
    devReadable?: boolean
    updatedBy: string
    valueUpdatedAt?: number
  }[]
  limit: number
}