Skip to content

/ api reference

Environment variables

Variables are managed per project, one entry per key, with a value in each environment that has it. Values are encrypted at rest, and a secret's value is never returned by any route.

A deployment reads its variables when it's built: redeploy after a change.

List variables

get/api/v1/projects/{projectId}/variables

One entry per key, with its value in each of the project's environments. A secret's value is never returned, by this route or any other; sameValue says whether every environment holds the same one. value at the top level is set when sameValue is true and the variable is not secret.

Requires Viewer key or above (workspace.read)

Parameters

  • projectIdstringin pathrequired

Responses

  • 200The project's environments and variables.
    Response fields
    • environmentsobject[]required
      3 fields
      • idstringrequired
      • namestringrequired
      • activeDeploymentIdstring | nullrequired
    • variablesobject[]required
      7 fields
      • keystringrequired
      • secretbooleanrequired
      • notestring | nullrequired
      • sameValuebooleanrequired
      • valuestring
      • updatedAtstringrequired
      • environmentsobject[]required
        4 fields
        • environmentIdstringrequired
        • secretbooleanrequired
        • valuestring
        • updatedAtstringrequired
  • 404No such project in this workspace.
Request
curl "https://api.hiraiship.com/api/v1/projects/$PROJECT_ID/variables" \
  -H "Authorization: Bearer $HIRAISHIP_TOKEN"

Create variables

post/api/v1/projects/{projectId}/variables

Sets up to 100 variables, with the same values, in each of environmentIds. Values are encrypted at rest. All or nothing: if a key already exists in one of the environments, nothing is written and the 409 lists every conflict. A running deployment reads new values only once redeployed.

Requires Developer key or above (variables.write)

Parameters

  • projectIdstringin pathrequired

Body

  • secretbooleanrequired
  • environmentIdsstring[]required

    at least 1 item

  • variablesobject[]required

    at least 1 item · at most 100 items

    3 fields
    • keystringrequired

      matches ^[A-Z_][A-Z0-9_]*$

    • valuestringrequired

      at most 4096 characters

    • notestring | null

      at most 500 characters

Responses

  • 201The created variables.
    Response fields
    • variablesobject[]required
      7 fields
      • keystringrequired
      • secretbooleanrequired
      • notestring | nullrequired
      • sameValuebooleanrequired
      • valuestring
      • updatedAtstringrequired
      • environmentsobject[]required
        4 fields
        • environmentIdstringrequired
        • secretbooleanrequired
        • valuestring
        • updatedAtstringrequired
  • 404No such project in this workspace.
  • 409Some keys already exist in the chosen environments.

    Body: see Errors

  • 422An environment of another project, the same key twice, or more than an environment's 100 variables.
Request
curl -X POST "https://api.hiraiship.com/api/v1/projects/$PROJECT_ID/variables" \
  -H "Authorization: Bearer $HIRAISHIP_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "secret": true,
    "environmentIds": [
      "9a1b7c3d-5e2f-4a8b-b6c4-2d8e1f9a5c31"
    ],
    "variables": [
      {
        "key": "STRIPE_SECRET_KEY",
        "value": "sk_live_…",
        "note": "Live key"
      }
    ]
  }'

Update a variable

patch/api/v1/projects/{projectId}/variables/{key}

Every field is optional. key renames it, secret: true hides its values from now on, and environments is the full set of environments the variable is kept in: one left out loses it, one with no value keeps its own, and an added one with no value takes the value the others share (when they differ, it needs one). A secret can never become a plain variable again.

Requires Developer key or above (variables.write)

Parameters

  • projectIdstringin pathrequired
  • keystringin pathrequired

Body

  • keystring

    matches ^[A-Z_][A-Z0-9_]*$

  • secretboolean
  • notestring | null

    at most 500 characters

  • environmentsobject[]

    at least 1 item

    2 fields
    • environmentIdstringrequired

      uuid

    • valuestring

      at most 4096 characters

Responses

  • 200The variable.
    Response fields
    • keystringrequired
    • secretbooleanrequired
    • notestring | nullrequired
    • sameValuebooleanrequired
    • valuestring
    • updatedAtstringrequired
    • environmentsobject[]required
      4 fields
      • environmentIdstringrequired
      • secretbooleanrequired
      • valuestring
      • updatedAtstringrequired
  • 404No such project in this workspace, or no variable with that key.
  • 409The new key already exists in one of the environments.

    Body: see Errors

  • 422A secret turned back into a plain variable, an environment of another project, an added environment with no value while the others differ, or more than 100 variables in one environment.
Request
curl -X PATCH "https://api.hiraiship.com/api/v1/projects/$PROJECT_ID/variables/$KEY" \
  -H "Authorization: Bearer $HIRAISHIP_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "environments": [
      {
        "environmentId": "9a1b7c3d-5e2f-4a8b-b6c4-2d8e1f9a5c31",
        "value": "https://api.acme.dev"
      },
      {
        "environmentId": "4e8c2a6f-7b1d-4c9e-a3f5-6b2d8e1c7a42",
        "value": "https://staging-api.acme.dev"
      }
    ]
  }'

Delete a variable

delete/api/v1/projects/{projectId}/variables/{key}

Removes the key from every environment of the project.

Requires Developer key or above (variables.write)

Parameters

  • projectIdstringin pathrequired
  • keystringin pathrequired

Responses

  • 204Deleted.
  • 404Project not found, or no variable with that key.
Request
curl -X DELETE "https://api.hiraiship.com/api/v1/projects/$PROJECT_ID/variables/$KEY" \
  -H "Authorization: Bearer $HIRAISHIP_TOKEN"