> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a workspace secret

> Store a credential once, reference it as ${NAME} in adapter headers, and never see it in a response again.

A secret is a value your agents need and you never want back. Store it here, reference it by name in a [tool set](/docs/api-reference/toolservice/create-a-new-tool-set) adapter's headers, and Cadenya substitutes it at call time.

<CodeGroup>
  ```typescript TypeScript theme={null}
  await client.workspaceSecrets.create({
    workspaceId,
    metadata: { name: 'DEMO_TOKEN' },
    spec: { value: process.env['DEMO_TOKEN']! },
  });
  ```

  ```go Go theme={null}
  _, err := client.WorkspaceSecrets.New(ctx,
  	cadenya.WorkspaceSecretNewParams{
  		WorkspaceID: cadenya.String(workspaceID),
  		Metadata: shared.CreateResourceMetadataParam{
  			Name: "DEMO_TOKEN",
  		},
  		Spec: cadenya.WorkspaceSecretSpecParam{
  			Value: cadenya.String(os.Getenv("DEMO_TOKEN")),
  		},
  	})
  ```

  ```ruby Ruby theme={null}
  cadenya.workspace_secrets.create(
    workspace_id: workspace_id,
    metadata: {name: "DEMO_TOKEN"},
    spec: {value: ENV["DEMO_TOKEN"]}
  )
  ```

  ```bash cURL theme={null}
  curl -X POST "https://api.cadenya.com/v1/workspaces/${WORKSPACE_ID}/workspace_secrets" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}" \
    -H "Content-Type: application/json" \
    -d '{ "metadata": { "name": "DEMO_TOKEN" }, "spec": { "value": "..." } }'
  ```
</CodeGroup>

Then reference it wherever an adapter takes headers:

```json theme={null}
{ "adapter": { "type": "http", "http": {
    "baseUrl": "https://api.example.com",
    "headers": { "Authorization": "Bearer ${DEMO_TOKEN}" }
} } }
```

## The value is write-only

`spec.value` never comes back. Not on read, not even on the create response, which returns `{"value": ""}`. There is no endpoint that reveals a stored secret.

The name doubles as the external ID: create `DEMO_TOKEN` and `metadata.externalId` is set to `DEMO_TOKEN` for you. Names are unique within a workspace, so a second `DEMO_TOKEN` is a `409`.

Rotate by updating the value in place, with a field mask:

```typescript theme={null}
await client.workspaceSecrets.update(secretId, {
  workspaceId,
  spec: { value: newValue },
  updateMask: 'spec.value',
});
```

## Three scopes, narrowest wins

The same name can exist at three levels. When a tool call resolves `${DEMO_TOKEN}`, Cadenya checks them in order and the first hit wins.

| Scope         | Where it lives                                                                          | Reach                            |
| ------------- | --------------------------------------------------------------------------------------- | -------------------------------- |
| **Objective** | `secrets` on [create-objective](/docs/api-reference/objectiveservice/create-a-new-objective) | One run                          |
| **Tool set**  | `tool_sets/{toolSetId}/secrets`                                                         | Every call through that provider |
| **Workspace** | Here                                                                                    | Everything in the workspace      |

That ordering is what makes per-user credentials work. The workspace holds your service account. The objective carries the token of whoever is asking. The same tool, the same header, a different identity per run.

```typescript theme={null}
await client.objectives.create({
  workspaceId,
  agentId: 'external_id:support',
  systemPromptData: {},
  firstUserMessage: 'Fetch this user\'s recent orders.',
  secrets: [{ name: 'DEMO_TOKEN', value: callerToken }], // beats the workspace secret
});
```

## Prove which one won

You never see a secret's value, but you can always see **which scope supplied it**. Read the tool call and `resolvedSecrets` names the key and its source.

```typescript theme={null}
const call = await client.objectives.toolCalls.retrieve(objectiveId, toolCallId, { workspaceId });
console.log(call.resolvedSecrets);
// [ { key: 'DEMO_TOKEN', source: 'RESOLVED_SECRET_SOURCE_OBJECTIVE' } ]
```

Running the same agent three times, adding one scope each time, shows the shadowing directly:

| Secrets present                  | `source` on the tool call          |
| -------------------------------- | ---------------------------------- |
| Workspace only                   | `RESOLVED_SECRET_SOURCE_WORKSPACE` |
| Workspace + tool set             | `RESOLVED_SECRET_SOURCE_TOOLSET`   |
| Workspace + tool set + objective | `RESOLVED_SECRET_SOURCE_OBJECTIVE` |

<Note>
  `resolvedSecrets` appears on the tool call **detail** view, not on items from the tool calls list. Fetch the call by ID.
</Note>

This is the tool to reach for when an agent authenticates as the wrong identity. The header looks right and the value is invisible, so the source field is the only evidence you get.

## Interpolation rules

`${NAME}` is substituted into adapter `headers` at call time, and for an HTTP tool also into the path, query, and request body template. The value never enters the model's context, and it is not written to the event timeline.

A reference that resolves to nothing is not silently blank. A tool set whose adapter names a secret that does not exist fails its sync with an `unresolved_secrets` error, so a typo surfaces when you create the tool set rather than when an agent calls it.

<Warning>
  Never inline a real credential in an adapter header. It would be stored in the tool set spec, which **is** returned on read. Always use a `${NAME}` reference.
</Warning>

## Related

<CardGroup cols={2}>
  <Card title="Store and use secrets" icon="key" href="/docs/guides/store-and-use-secrets">
    The hands-on lesson, from secret to authenticated tool call.
  </Card>

  <Card title="Create a tool set" icon="wrench" href="/docs/api-reference/toolservice/create-a-new-tool-set">
    Where `${NAME}` gets referenced, and tool-set-scoped secrets live.
  </Card>

  <Card title="Create an objective" icon="bullseye" href="/docs/api-reference/objectiveservice/create-a-new-objective">
    Per-run secrets, for short-lived per-user tokens.
  </Card>

  <Card title="Secrets" icon="lock" href="/docs/guides/secrets">
    How resolution works, and what never leaves the vault.
  </Card>
</CardGroup>


## OpenAPI

````yaml post /v1/workspaces/{workspaceId}/workspace_secrets
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/workspaces/{workspaceId}/workspace_secrets:
    post:
      tags:
        - WorkspaceSecretService
        - Workspace Secrets
      summary: Create a new workspace secret
      description: Creates a new workspace secret in the workspace
      operationId: WorkspaceSecretService_CreateWorkspaceSecret
      parameters:
        - name: workspaceId
          in: path
          description: The workspace that will own this secret.
          required: true
          schema:
            type: string
            example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateWorkspaceSecretRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WorkspaceSecret'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import Cadenya from '@cadenya/cadenya';

            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });

            const workspaceSecret = await client.workspaceSecrets.create({
              workspaceId: 'workspace_01HXKD2E5NQM3T9AYWCF133E3Q',
              metadata: { name: 'name' },
              spec: {},
            });

            console.log(workspaceSecret.metadata);
        - lang: Python
          source: |-
            import os
            from cadenya import Cadenya

            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )
            workspace_secret = client.workspace_secrets.create(
                workspace_id="workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
                metadata={
                    "name": "name"
                },
                spec={},
            )
            print(workspace_secret.metadata)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n\t\"go.cadenya.com/cadenya-go/shared\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tworkspaceSecret, err := client.WorkspaceSecrets.New(context.TODO(), cadenya.WorkspaceSecretNewParams{\n\t\tWorkspaceID: cadenya.String(\"workspace_01HXKD2E5NQM3T9AYWCF133E3Q\"),\n\t\tMetadata: shared.CreateResourceMetadataParam{\n\t\t\tName: \"name\",\n\t\t},\n\t\tSpec: cadenya.WorkspaceSecretSpecParam{},\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", workspaceSecret.Metadata)\n}\n"
        - lang: Ruby
          source: |-
            require "cadenya"

            cadenya = Cadenya::Client.new(api_key: "My API Key")

            workspace_secret = cadenya.workspace_secrets.create(
              workspace_id: "workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
              metadata: {name: "name"},
              spec: {}
            )

            puts(workspace_secret)
        - lang: CLI
          source: |-
            cadenya workspace-secrets create \
              --api-key 'My API Key' \
              --workspace-id workspace_01HXKD2E5NQM3T9AYWCF133E3Q \
              --metadata '{name: name}' \
              --spec '{}'
components:
  schemas:
    CreateWorkspaceSecretRequest:
      required:
        - metadata
        - spec
      type: object
      properties:
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: The workspace that will own this secret.
        metadata:
          $ref: '#/components/schemas/CreateResourceMetadata'
        spec:
          $ref: '#/components/schemas/WorkspaceSecretSpec'
    WorkspaceSecret:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/ResourceMetadata'
        spec:
          $ref: '#/components/schemas/WorkspaceSecretSpec'
        info:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/WorkspaceSecretInfo'
          description: Workspace secret information
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    CreateResourceMetadata:
      required:
        - name
      type: object
      properties:
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
      description: |-
        CreateResourceMetadata contains the user-provided fields for creating
         a workspace-scoped resource. Read-only fields (id, account_id, workspace_id, profile_id,
         created_at) are excluded since they are set by the server.
    WorkspaceSecretSpec:
      type: object
      properties:
        value:
          type: string
    ResourceMetadata:
      required:
        - id
        - accountId
        - workspaceId
        - name
        - profileId
        - createdAt
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "agent_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: >-
            Workspace this resource belongs to for organizational grouping
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
          description: ID of the actor (user or service account) that created this resource
        createdAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was created
          format: date-time
        updatedAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was last updated
          format: date-time
      description: >-
        Standard metadata for persistent, named resources (e.g., agents, tools,
        prompts)
    WorkspaceSecretInfo:
      type: object
      properties:
        lastUsedAt:
          readOnly: true
          type: string
          format: date-time
        createdBy:
          $ref: '#/components/schemas/Profile'
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
    Profile:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/ProfileSpec'
      description: |-
        A profile identifies a user or non-human principal (such as an API key)
         at the account level. Profiles are account-scoped and can be granted access
         to multiple workspaces.
    AccountResourceMetadata:
      required:
        - id
        - accountId
        - name
        - profileId
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "apikey_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
        createdAt:
          readOnly: true
          type: string
          format: date-time
      description: >-
        AccountResourceMetadata is used to represent a resource that is
        associated to an account but not to a workspace.
    ProfileSpec:
      required:
        - type
      type: object
      properties:
        email:
          type: string
          description: >-
            Email address of the profile. Required and unique within an account
            for
             user profiles.
        name:
          type: string
          description: Display name (e.g., "Bobby Tables").
        type:
          enum:
            - PROFILE_TYPE_UNSPECIFIED
            - PROFILE_TYPE_USER
            - PROFILE_TYPE_API_KEY
            - PROFILE_TYPE_SYSTEM
          type: string
          description: >-
            Whether this profile represents a human user, an API key, or a
            system
             principal.
          format: enum
      description: Configuration for a profile.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````