# Secrets

> Secrets are values a run can type without them being written into a skill: passwords, one-time codes, card numbers. The API only returns their names.

A secret is a value a run can type without it being written into a skill: a password, a one-time code, a card number. Write `{{secret:name}}` in a step and the run fills it in on the phone. The API only ever gives back a secret's name.

## Endpoints

- `GET /v1/secrets` (scope `runs:write`): The names of your secrets and when each was last set.
- `PUT /v1/secrets/{name}` (scope `runs:write`): Sets a secret with `{ value }`, up to 500 characters. Names are lowercase letters, digits and underscores, starting with a letter.
- `DELETE /v1/secrets/{name}` (scope `runs:write`): Deletes a secret.

Source: https://distilled.cx/docs/secrets/
