Create a secret
Create an encrypted Runpod account secret that Pods, Serverless endpoints, and templates can reference from environment variables at boot.
Authorizations
Runpod API key authentication. Generate an API key in the Runpod console and send it in the Authorization header as Bearer <api_key>. Keys are scoped to the permissions granted when created; requests may return 403 when a valid key lacks access to the requested resource or action.
Body
Unique name for the secret — referenced from environment variables as {{ RUNPOD_SECRET_<name> }}; immutable after creation. Maximum 191 characters, must start with a letter or underscore, and may contain letters, digits, and _.-/. Names beginning with the reserved prefix RUNPOD are rejected (case-insensitive).
1 - 191^[a-zA-Z_][a-zA-Z0-9_.\-/]*$"hf-token"
The secret value. Write-only — never returned by the API. Must be smaller than 16 MiB of UTF-8 text (strictly under 16,777,216 bytes).
1 - 16777216Optional human-readable description, at most 65,535 bytes of UTF-8 text.
65535"Hugging Face read token"
Response
Created
An account-scoped secret: an encrypted string stored by Runpod, referenced from pod, serverless, and template environment variables with the {{ RUNPOD_SECRET_<name> }} placeholder, substituted with the secret's value when the pod or worker boots. The value is write-only and never returned by the API.
Unique secret identifier
"2q9m7x4cavgd"
Unique, human-readable name — the <name> referenced by the RUNPOD_SECRET_<name> placeholder. Immutable after creation.
"hf-token"
When the secret was created
Human-readable description
"Hugging Face read token"
When the secret's value was last set (creation or rotation)