> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnara.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List secrets visible through ownership authority

> Items are ordered by created_at descending, then id descending. Without an owner filter, returns the deduplicated union of organization secrets the caller may list, project secrets the caller may list, and the caller's own user secrets.



## OpenAPI

````yaml /api-reference/openapi.yaml get /orgs/{orgID}/secrets
openapi: 3.1.2
info:
  title: Omnara API
  version: 0.1.0
  description: Public HTTP API contract for Omnara.
servers:
  - url: https://api.omnara.com/v1
    description: Hosted Omnara
security:
  - bearerAuth: []
  - browserSessionCookie: []
tags:
  - name: Agents
    description: >-
      Launch agents, send inputs, manage the input backlog, and work with tool
      calls.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/agents/overview
  - name: Interactions
    description: List and resolve the approvals and questions that pause an agent.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/events/interactions
  - name: Actors
    description: Attribute agent inputs and interaction responses to external users.
    externalDocs:
      description: Guide
      url: >-
        https://docs.omnara.com/events/sending-input#who-said-that-actors-and-attribution
  - name: Events
    description: Read or stream the agent timeline, list turns, and download artifacts.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/events/streaming
  - name: Configs and Profiles
    description: >-
      Create agent configs, manage reusable launch profiles, and set up
      integrations.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/agents/configuration
  - name: Models
    description: Configure model providers and models, and grant projects access to them.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/organization/model-providers
  - name: Machines
    description: Register machines, control project access, and manage daemon tokens.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/machines/connect
  - name: Machine Pools
    description: Define machine pools and grant projects access to them.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/machines/pools
  - name: Secrets
    description: >-
      Manage secret ownership and versions, and inspect or grant project
      availability.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/organization/secrets
  - name: Skills
    description: Manage versioned skill ownership and load skill instructions on demand.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/tools/skills
  - name: Organizations and Projects
    description: Create organizations and projects and manage membership.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/organization/members
  - name: Users and API Keys
    description: >-
      The authenticated user, personal and organization API keys, and
      invitations.
    externalDocs:
      description: Guide
      url: https://docs.omnara.com/api/authentication
  - name: Machine Daemon
    description: Routes the Omnara machine daemon uses to connect a machine.
paths:
  /orgs/{orgID}/secrets:
    parameters:
      - name: orgID
        in: path
        required: true
        schema:
          type: string
          pattern: ^org_[a-z2-7]{26}$
    get:
      tags:
        - Secrets
      summary: List secrets visible through ownership authority
      description: >-
        Items are ordered by created_at descending, then id descending. Without
        an owner filter, returns the deduplicated union of organization secrets
        the caller may list, project secrets the caller may list, and the
        caller's own user secrets.
      operationId: listSecrets
      parameters:
        - $ref: '#/components/parameters/ResourceNameFilter'
        - $ref: '#/components/parameters/SecretKindFilter'
        - $ref: '#/components/parameters/SecretOwnerKindFilter'
        - $ref: '#/components/parameters/SecretOwnerProjectIDFilter'
        - $ref: '#/components/parameters/SecretMCPOAuthFlowIDFilter'
        - $ref: '#/components/parameters/SecretMetadataFilter'
        - name: sort
          in: query
          schema:
            $ref: '#/components/schemas/ResourceListSort'
        - $ref: '#/components/parameters/PageLimit'
        - $ref: '#/components/parameters/PageCursor'
      responses:
        '200':
          description: Secrets visible through ownership authority.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListSecretsResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
        4XX:
          $ref: '#/components/responses/ClientError'
        5XX:
          $ref: '#/components/responses/ServerError'
components:
  parameters:
    ResourceNameFilter:
      name: name
      in: query
      required: false
      schema:
        type: string
        minLength: 1
        maxLength: 200
      description: >-
        Case-insensitive glob over the list's logical name. `*` matches zero or
        more characters, `?` matches one character, and `\` escapes a wildcard.
    SecretKindFilter:
      name: kind
      in: query
      required: false
      schema:
        $ref: '#/components/schemas/SecretKind'
      description: Filter secrets by material kind.
    SecretOwnerKindFilter:
      name: owner_kind
      in: query
      required: false
      schema:
        type: string
        enum:
          - org
          - project
          - user
      description: Filter by the immutable owner kind.
    SecretOwnerProjectIDFilter:
      name: owner_project_id
      in: query
      required: false
      schema:
        $ref: '#/components/schemas/ProjectID'
      description: Required with owner_kind=project and invalid with other owner kinds.
    SecretMCPOAuthFlowIDFilter:
      name: mcp_oauth_flow_id
      in: query
      required: false
      schema:
        $ref: '#/components/schemas/MCPOAuthFlowID'
      description: Filter to secrets that have a version created by this MCP OAuth flow.
    SecretMetadataFilter:
      name: metadata
      in: query
      required: false
      style: deepObject
      explode: true
      description: Metadata key/value filters, encoded as metadata[key]=value.
      schema:
        type: object
        additionalProperties:
          type: string
    PageLimit:
      name: limit
      in: query
      required: false
      schema:
        type: integer
        format: int32
        minimum: 1
        maximum: 100
        default: 50
      description: Maximum number of items to return in one page.
    PageCursor:
      name: cursor
      in: query
      required: false
      schema:
        type: string
        maxLength: 1024
      description: >-
        Opaque pagination cursor from a previous response's next_cursor. Omit
        for the first page.
  schemas:
    ResourceListSort:
      type: string
      description: >-
        Sort order for named resources that expose created and modified
        timestamps.
      default: '-created_at'
      enum:
        - name
        - '-name'
        - '-updated_at'
        - updated_at
        - '-created_at'
        - created_at
    ListSecretsResponse:
      type: object
      additionalProperties: false
      required:
        - data
        - next_cursor
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/Secret'
        next_cursor:
          type:
            - string
            - 'null'
    SecretKind:
      type: string
      enum:
        - generic
        - oauth_token_set
        - slack_app_credentials
        - aws_credentials
      x-enum-varnames:
        - SecretKindGeneric
        - SecretKindOAuthTokenSet
        - SecretKindSlackAppCredentials
        - SecretKindAWSCredentials
    ProjectID:
      type: string
      pattern: ^proj_[a-z2-7]{26}$
    MCPOAuthFlowID:
      type: string
      pattern: ^moaf_[a-z2-7]{26}$
    Secret:
      type: object
      additionalProperties: false
      required:
        - id
        - org_id
        - management_kind
        - owner
        - name
        - kind
        - metadata
        - current_version_number
        - payload_keys
        - created_at
        - updated_at
      properties:
        id:
          $ref: '#/components/schemas/SecretID'
        org_id:
          $ref: '#/components/schemas/OrganizationID'
        management_kind:
          $ref: '#/components/schemas/ManagementKind'
        owner:
          $ref: '#/components/schemas/SecretOwner'
        name:
          $ref: '#/components/schemas/ResourceName'
        kind:
          $ref: '#/components/schemas/SecretKind'
        metadata:
          $ref: '#/components/schemas/Metadata'
        current_version_number:
          type: integer
          format: int32
        payload_keys:
          type: array
          items:
            type: string
        created_at:
          $ref: '#/components/schemas/Timestamp'
        updated_at:
          $ref: '#/components/schemas/Timestamp'
    Error:
      type: object
      additionalProperties: false
      required:
        - error
        - code
      properties:
        error:
          type: string
          description: Human-readable error message. Do not match on it programmatically.
        code:
          type: string
          description: Stable error code for programmatic handling.
          enum:
            - invalid_request
            - unauthorized
            - forbidden
            - not_found
            - conflict
            - gone
            - request_too_large
            - unsupported_media_type
            - unprocessable
            - rate_limited
            - internal_error
            - upstream_error
            - service_unavailable
            - idempotency_key_conflict
            - state_transition_conflict
            - managed_work_admission_denied
            - pending_work
            - not_wake_capable
            - daemon_runtime_unregistered
            - validation_failed
            - csrf_check_failed
            - authentication_unavailable
    ClientErrorCode:
      type: string
      description: >-
        Stable error code carried by 4XX statuses. Subset of the Error code enum
        whose statuses are client errors.
      enum:
        - invalid_request
        - validation_failed
        - unauthorized
        - forbidden
        - csrf_check_failed
        - not_found
        - conflict
        - idempotency_key_conflict
        - state_transition_conflict
        - pending_work
        - not_wake_capable
        - gone
        - daemon_runtime_unregistered
        - request_too_large
        - unsupported_media_type
        - unprocessable
        - rate_limited
    ServerErrorCode:
      type: string
      description: >-
        Stable error code carried by 5XX statuses. Subset of the Error code enum
        whose statuses are server errors.
      enum:
        - internal_error
        - upstream_error
        - service_unavailable
        - authentication_unavailable
    SecretID:
      type: string
      pattern: ^sec_[a-z2-7]{26}$
    OrganizationID:
      type: string
      pattern: ^org_[a-z2-7]{26}$
    ManagementKind:
      type: string
      description: >-
        Lifecycle owner. Tenant-managed resources can be changed through tenant
        APIs. Cluster-managed resources are installed and lifecycle-managed by
        the control plane; individual APIs may explicitly expose tenant-editable
        settings.
      enum:
        - tenant
        - cluster
    SecretOwner:
      oneOf:
        - $ref: '#/components/schemas/OrgSecretOwner'
        - $ref: '#/components/schemas/ProjectSecretOwner'
        - $ref: '#/components/schemas/UserSecretOwner'
      discriminator:
        propertyName: kind
        mapping:
          org:
            $ref: '#/components/schemas/OrgSecretOwner'
          project:
            $ref: '#/components/schemas/ProjectSecretOwner'
          user:
            $ref: '#/components/schemas/UserSecretOwner'
    ResourceName:
      type: string
      minLength: 1
      maxLength: 64
      x-omnara-unicode-normalization: NFC
      description: >-
        Human-readable name. Spaces and punctuation are allowed; leading or
        trailing whitespace and invisible or control characters are not.
    Metadata:
      type: object
      description: >-
        Arbitrary key-value metadata. Maximum 16 pairs, keys up to 64
        characters, values must be strings of up to 512 characters.
      x-go-type: resourcemeta.Metadata
      x-go-type-import:
        path: github.com/omnara-ai/omnara/internal/resourcemeta
      x-go-type-skip-optional-pointer: true
      maxProperties: 16
      propertyNames:
        minLength: 1
        maxLength: 64
      additionalProperties:
        type: string
        maxLength: 512
    Timestamp:
      type: string
      format: date-time
    OrgSecretOwner:
      type: object
      additionalProperties: false
      required:
        - kind
      properties:
        kind:
          type: string
          enum:
            - org
    ProjectSecretOwner:
      type: object
      additionalProperties: false
      required:
        - kind
        - project_id
      properties:
        kind:
          type: string
          enum:
            - project
        project_id:
          $ref: '#/components/schemas/ProjectID'
    UserSecretOwner:
      type: object
      additionalProperties: false
      required:
        - kind
        - user_id
      properties:
        kind:
          type: string
          enum:
            - user
        user_id:
          $ref: '#/components/schemas/UserID'
    UserID:
      type: string
      pattern: ^usr_[a-z2-7]{26}$
  responses:
    BadRequest:
      description: The request was invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Authentication is required or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: The authenticated principal is not authorized.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The requested resource was not found or is not visible.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: An unexpected internal server error occurred.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    ServiceUnavailable:
      description: The service dependency required to satisfy the request is unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    ClientError:
      description: >-
        Any other client error. The body carries the shared Error envelope
        restricted to client error codes; statuses with a dedicated response
        above are documented precisely.
      content:
        application/json:
          schema:
            type: object
            additionalProperties: false
            required:
              - error
              - code
            properties:
              error:
                type: string
                description: >-
                  Human-readable error message. Do not match on it
                  programmatically.
              code:
                $ref: '#/components/schemas/ClientErrorCode'
    ServerError:
      description: >-
        Any other server error. The body carries the shared Error envelope
        restricted to server error codes.
      content:
        application/json:
          schema:
            type: object
            additionalProperties: false
            required:
              - error
              - code
            properties:
              error:
                type: string
                description: >-
                  Human-readable error message. Do not match on it
                  programmatically.
              code:
                $ref: '#/components/schemas/ServerErrorCode'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Omnara personal or organization access token
      description: An opaque Omnara personal or organization bearer token.
    browserSessionCookie:
      type: apiKey
      in: cookie
      name: __Host-omnara_session
      description: >-
        Browser session cookie. HTTPS deployments use __Host-omnara_session;
        local HTTP development uses omnara_session.

````