Replace secrets
Sets one secret on a codebase.
PUT /v1/environment/{repo}/secrets/{name}
| Address | https://api.hanzo.ai/v1/environment/{repo}/secrets/{name} |
| Method | PUT |
| Operation | put_environment_by_repo_secrets_by_name |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Sets one secret on a codebase.
The value is sealed in KMS and exported to every later sandbox run on this codebase under its name, a setup run included. It is blinded out of every stream the run publishes, and no route answers it back. Setting a name that is already set replaces its value. Org admin only.
Request
5 fields, body application/json (required).
| Field | In | Type | Required | Description |
|---|---|---|---|---|
repo | path | string | yes | Repo is the repository's name in the caller's org. |
name | path | string | yes | Name is the environment variable the run exports the value under. |
name | body | string | — | Name is the environment variable the run exports the value under. |
repo | body | string | — | Repo is the repository's name in the caller's org. |
value | body | string | — | Value is sealed in KMS and never answered, logged or echoed. |
Response
| Status | Body | Meaning |
|---|---|---|
200 | environment.Environment | ok |
default | problem-details | refused |
200 body — 12 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
install | body | string | — | Install is the shell a run executes in its fresh checkout before the agent starts, from the repository root. |
proposal | body | environment.Proposal | — | |
proposal.install | body | string | — | Install is the install script the agent checked. |
proposal.note | body | string | — | Note is what the agent found and checked, in its own words. |
proposal.secrets | body | string[] | — | Secrets are the environment variables the agent found the codebase reads. |
proposal.start | body | string | — | Start is the start command the agent checked, or empty. |
repo | body | string | — | Repo is the codebase: a repository's name in the caller's org. |
secrets | body | string[] | — | Secrets are the names set on this codebase, each exported to the run's commands under that name. |
session | body | string | — | Session is the setup run that produced the proposal, when there is one. |
start | body | string | — | Start is the one command a run leaves running in the background once the install has finished — a dev server, a database. |
state | body | string | — | State is none when nothing is saved or proposed, proposed when a setup run's answer is waiting to be reviewed, and ready otherwise. |
updatedAt | body | string | — | UpdatedAt is when this environment last changed, RFC 3339. |
Failure carries the platform error shape — see Errors.
Examples
hanzo has no subcommand for this operation — the CLI serves only what cloud's live route table confirms. Use HTTP or an SDK.
import { Configuration, EnvironmentApi } from 'hanzoai';
const api = new EnvironmentApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.putEnvironmentByRepoSecretsByName({ repo: 'repo', name: 'name', name: "<name>", repo: "<repo>" });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import EnvironmentApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = EnvironmentApi(client).put_environment_by_repo_secrets_by_name(repo='repo', name='name', name="<name>", repo="<repo>")cfg := hanzoai.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := hanzoai.NewAPIClient(cfg)
resp, _, err := client.EnvironmentAPI.PutEnvironmentByRepoSecretsByName(context.Background()).Execute()
if err != nil {
return err
}use hanzo_client::apis::{configuration::Configuration, environment_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = environment_api::put_environment_by_repo_secrets_by_name(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.EnvironmentApi;
ApiClient client = new ApiClient();
client.setBearerToken(System.getenv("HANZO_API_KEY"));
var result = new EnvironmentApi(client).putEnvironmentByRepoSecretsByName();curl -X PUT https://api.hanzo.ai/v1/environment/<repo>/secrets/<name> \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "<name>",
"repo": "<repo>"
}'MCP reaches environment through the environment tool, which names its 4 operations with its own verbs — this one among them, under a name only MCP declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "list_environments"
}
}
}'