Skip to main content
DELETE
Delete a secret

Authorizations

Authorization
string
header
required

Your Reason API key from Settings > API. New keys use reason_; legacy ara_ keys remain accepted. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:debug is privileged: it expands diagnostic session events only for organization owners/admins.

Path Parameters

orgId
string
required

Organization id or slug. Resolve it with GET /v3/self.

secretId
string
required

The secret name.

Query Parameters

scope
enum<string>
default:user
Available options:
organization,
user,
repo
repo
string

Deprecated context field for the repo compatibility scope. The repository no longer changes storage; the secret is workspace-wide.

provider
enum<string>

Deprecated provider context for the repo compatibility scope.

Available options:
github

Response

200 - application/json

Success.