Create a Secret
create_secretCreate an org-scoped secret whose values never pass through this chat. With values "generate", Control Plane fills dictionary keys or an opaque payload with random values now. With values "user", returns a Console link prefilled with the name, type, and keys where the user types the values. No input accepts a value and no result contains one. Databases through add_database get their credentials without this tool. A workload reads a key as cpln://secret/NAME.KEY; deploy_app grants the access, grant_workload_secret_access does it for an existing workload.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| org | No | Organization slug. | |
| keys | No | Dictionary key names. Required to generate a dictionary. For "user", prefills the Console form with these keys. | |
| name | Yes | Name for the new org-scoped secret. Pass the name only; names are immutable. | |
| type | Yes | Secret type. Generated values support "dictionary" (one value per key) and "opaque" (one payload). | |
| length | No | Generated value length in characters (default 32). Only with values "generate". | |
| values | Yes | Who supplies the values. "generate": Control Plane fills them with random values now and nobody sees them, for values nobody needs to know (database passwords, signing and session keys, internal tokens). "user": returns a Console link where the user types them, for values only the user has (third-party keys, existing credentials, certificates). Nothing is created in "user" mode until the user saves the form. | |
| charset | No | Generated value alphabet (default "alphanumeric", which is safe in connection strings). Only with values "generate". | |
| description | No | Optional description shown on the secret. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ok | Yes | ||
| data | No | The full result. Read this, not only the summary. | |
| details | No | ||
| summary | Yes | ||
| nextSteps | No |