promote_secret
Copies a secret's value from one environment to another without exposing it outside the keyring. Avoids overwriting a differing target unless force is enabled; no-op when values already match.
Instructions
[secrets] Copy one secret's value from a source environment to a target environment (superposition states), e.g. staging → prod, without the value ever leaving the keyring. Use when an environment must match another for a single key; use diff_environments first to see what differs. Refuses to overwrite a differing target unless force is true; a target that already matches is a no-op. Mutates the keyring (one 'write' audit event, hooks fire) only when the target changes. Returns { key, scope, from, to, previous: 'absent'|'same'|'different', changed }. Never returns the value.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| to | Yes | Target environment state. Example: 'prod'. | |
| key | Yes | Secret key name. Example: 'DATABASE_URL'. | |
| from | Yes | Source environment state. Example: 'staging'. | |
| force | No | Overwrite a differing target value. Default false → the call fails with ERR_PROMOTE_CONFLICT instead. | |
| orgId | No | Organization identifier for org-scoped secrets. Required only when scope='org'. Example: 'acme-corp'. | |
| scope | No | Where the secret lives. 'global' = user keyring (default if omitted on reads), 'project' = scoped to projectPath, 'team' = team-shared (needs teamId), 'org' = org-shared (needs orgId). | global |
| teamId | No | Team identifier for team-scoped secrets. Required only when scope='team'. Example: 'acme-platform'. | |
| projectPath | No | Absolute path to the project root for project-scoped secrets and policy resolution. Defaults to the MCP server's current working directory when omitted. |