Sites
Reveal a site's secret
Returns the decrypted value for a single secret. This is a POST (not GET) so the secret never lands in a URL, request log, or browser history.
POST
Typescript (SDK)
Authorizations
API key in the format: Bearer {api_token}
Headers
Makes this write safe to retry: a repeat with the same key replays the first response instead of creating a second resource. Scoped to the account, remembered for 24 hours; reusing a key with a different payload is an error.
Maximum string length:
255Path Parameters
The resource ID (e.g., "prod_abc123") or slug (e.g., "my-product")
The secret's prefix ID (e.g., "secret_abc123")
Response
The secret, including its decrypted value

