> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Store a new version (becomes current)



## OpenAPI

````yaml /api-reference/specs/secrets.yaml post /v1/secrets/{secret_id}/value
openapi: 3.0.3
info:
  title: Basaltic Secrets API
  version: 1.0.0
  description: |
    Versioned application secrets with KMS-backed envelope encryption.

    Secrets are regional. The value of every version is encrypted at
    rest under a KMS key — only opaque ciphertext is persisted. By
    default a secret uses the platform-managed key; pass kms_key_id on
    CreateSecret to bind it to one of your own KMS keys instead (the key
    is fixed for the secret's life, and every version is encrypted under
    it). Each PutSecretValue allocates a new monotonically-increasing
    version number and flips is_current on the previous row; older
    versions remain readable by explicit version query.

    Soft delete: DeleteSecret moves the secret into a recovery window
    (default 7 days, configurable 1-30). RestoreSecret exits the
    window. The hard-purge sweeper removes the row + every version
    once now() >= scheduled_purge_at.

    Values move on the wire as base64 to survive arbitrary binary
    payloads (max 64 KiB to mirror AWS Secrets Manager).
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://secrets.{region}.basaltic.sh
    description: Regional API endpoint
    variables:
      region:
        default: sa-saopaulo-1
        description: Region code
security:
  - SignatureAuth: []
tags:
  - name: Secrets
    description: Secret metadata + value lifecycle
paths:
  /v1/secrets/{secret_id}/value:
    parameters:
      - $ref: '#/components/parameters/SecretId'
    post:
      tags:
        - Secrets
      summary: Store a new version (becomes current)
      operationId: putSecretValue
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PutSecretValueRequest'
      responses:
        '201':
          description: Version stored.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VersionResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: No such secret, or its KMS key does not exist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            Secret is scheduled for deletion, or its KMS key is disabled or
            pending deletion.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    SecretId:
      name: secret_id
      in: path
      required: true
      schema:
        type: string
        format: uuid
        example: a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: >-
        Optional client-generated key that makes a create replay-safe. Retrying
        a request with the same key returns the original outcome verbatim
        instead of creating a duplicate resource. Reusing a key with a different
        request body is rejected (422); a request whose key is still being
        processed returns 409. Records are honored for 24 hours. Use a UUID or
        similarly unique token.
      required: false
      schema:
        type: string
        maxLength: 255
      example: 550e8400-e29b-41d4-a716-446655440000
  schemas:
    PutSecretValueRequest:
      type: object
      required:
        - value
      properties:
        value:
          type: string
          format: byte
          description: Base64 of the new value bytes (1 byte - 64 KiB).
          example: bmV3LXNlY3JldC12YWx1ZQ==
    VersionResponse:
      type: object
      required:
        - version
      properties:
        version:
          $ref: '#/components/schemas/SecretVersion'
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
    SecretVersion:
      type: object
      required:
        - id
        - version
        - is_current
        - created_at
      properties:
        id:
          type: string
          format: uuid
          example: 9d8c7b6a-5e4f-4a3b-8c2d-1e0f9a8b7c6d
        version:
          type: integer
          example: 3
        is_current:
          type: boolean
          example: true
        created_by:
          type: string
          description: >-
            CRN of the principal that created this version (e.g.
            crn:iam:::user/<id>, crn:iam:::service-account/<id>).
          example: crn:iam:::user/5f3a2b1c-8d7e-4f6a-9b0c-1d2e3f4a5b6c
        created_at:
          type: string
          format: date-time
          example: '2026-01-18T11:45:00Z'
  responses:
    BadRequest:
      description: Invalid request parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_INPUT
              message: Invalid request parameters
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    UnprocessableEntity:
      description: |
        The request is well-formed but cannot be processed as sent. On the
        operations that accept `Idempotency-Key` this is the key-reuse case: the
        key was first seen with a different request payload, so replaying the
        stored outcome would answer a question the caller did not ask.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: IDEMPOTENCY_KEY_REUSED
              message: >-
                This Idempotency-Key was already used with a different request
                payload
              request_id: 550e8400-e29b-41d4-a716-446655440000
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: An internal error occurred
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    SignatureAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >
        Request signing with an access key issued to a service account. An

        HMAC-SHA256 over a canonical form of the request, close to AWS SigV4.

        The `basaltic` CLI signs for you.


        Send `Authorization`, `X-Date` (UTC, `YYYYMMDDTHHMMSSZ`) and `X-Nonce`

        (random per request); add `X-Content-Sha256` to bind a body, and

        `X-Amz-Security-Token` when using temporary credentials.


        ```

        Authorization: BASALTIC-HMAC-SHA256
        Credential=<access_key_id>/<date>/<region>/basaltic/basaltic_request,
        SignedHeaders=host;x-date;x-nonce, Signature=<hex>

        ```


        `<region>` is the region code you are calling, or `global` for the
        global

        services. A signature is valid for 5 minutes from `X-Date`, and mutating

        requests are replay-guarded on the nonce.


        **Full signing procedure, including a working implementation:**

        https://docs.basaltic.sh/authentication


        ## Rate limits

        There is no global request budget. A limit applies only where an

        operation documents a `429`, and that operation says what it counts.

        Those responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining`,

        `X-RateLimit-Reset` and, on a `429`, `Retry-After` — read them rather

        than hard-coding a number. Retrying before `Retry-After` is refused and

        extends the window. Everything else is bounded by quota, not by request

        rate.

````