> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browserbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a Secret

> Replace a secret's value. The name cannot be changed; to rename, create a new secret and delete the old one.



## OpenAPI

````yaml patch /v1/secrets/{id}
openapi: 3.0.0
info:
  title: Browserbase API
  description: Browserbase API for 3rd party developers
  version: v1
servers:
  - url: https://api.browserbase.com
    description: Public endpoint
    variables: {}
security:
  - BrowserbaseAuth: []
tags: []
paths:
  /v1/secrets/{id}:
    patch:
      summary: Update a Secret
      description: >-
        Replace a secret's value. The name cannot be changed; to rename, create
        a new secret and delete the old one.
      operationId: Secrets_update
      parameters:
        - name: id
          in: path
          description: The id of the project secret to update.
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                sealedSecretValue:
                  description: >-
                    The new secret value encrypted with HPKE. To seal the secret
                    value before sending, get the project's public key from GET
                    /v1/secrets/keypair. Decode the publicKey using base64 into
                    the raw 32-byte public key. Then, use HPKE Base mode (RFC
                    9180) with the following algorithm suite: DHKEM(X25519,
                    HKDF-SHA256), HKDF-SHA256, and AES-256-GCM. Set both info
                    and additional authenticated data (AAD) to an empty byte
                    string. Then, create a new sender context using the public
                    key and these settings, and encrypt the secret value as one
                    message. Put the 32-byte encapsulated key before the
                    ciphertext and keep the authentication tag at the end of the
                    ciphertext. Encode the combined bytes with standard base64.
                    Send the result as sealedSecretValue: base64(enc ||
                    ciphertext)
                  type: string
                keypairId:
                  description: >-
                    The `id` returned by GET /v1/secrets/keypair, identifying
                    the keypair whose public key encrypted the value. Recorded
                    with the secret so decryption stays correct across keypair
                    rotation.
                  type: string
              required:
                - sealedSecretValue
                - keypairId
      responses:
        '200':
          description: The updated secret.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Secret'
        '400':
          description: >-
            Invalid request, or keypairId does not identify an active keypair in
            the project. If the keypair is no longer active, fetch GET
            /v1/secrets/keypair, seal the value again, and retry.
          content:
            application/json:
              schema:
                type: object
                properties:
                  statusCode:
                    description: HTTP status code
                    type: integer
                  error:
                    description: HTTP error name
                    type: string
                  message:
                    description: Human-readable error message
                    type: string
                required:
                  - statusCode
                  - error
                  - message
        '404':
          description: The secret does not exist in the project.
          content:
            application/json:
              schema:
                type: object
                properties:
                  statusCode:
                    description: HTTP status code
                    type: integer
                  error:
                    description: HTTP error name
                    type: string
                  message:
                    description: Human-readable error message
                    type: string
                required:
                  - statusCode
                  - error
                  - message
components:
  schemas:
    Secret:
      type: object
      properties:
        id:
          description: Unique identifier of the secret.
          type: string
        secretKey:
          description: The name the secret value is stored under.
          type: string
      required:
        - id
        - secretKey
  securitySchemes:
    BrowserbaseAuth:
      type: apiKey
      in: header
      name: X-BB-API-Key
      description: Your [Browserbase API Key](https://www.browserbase.com/settings).

````