Secrets runtime reference
Use this page to compare how the JavaScript and Python SDKs read secrets. Manage secrets and secret types in TaruviBase Console.
Interface support#
| Interface | Current coverage |
|---|---|
| TaruviBase Console | Create, inspect, edit, and delete secret types and site/app secrets |
| JavaScript SDK | Runtime get and batch list |
| Python SDK | Runtime get and filtered or batch list, sync and async |
| History | Not available through Console or the SDKs |
SDK runtime read methods#
| Task | JavaScript SDK | Python SDK |
|---|---|---|
| Read one key | secrets.get(key, options).execute<SecretResponse>() | client.secrets.get(key, *, app=None, tags=None) |
| Retrieve several keys | await secrets.list(keys, options) | client.secrets.list(keys=[...], ...) |
| List and filter | Not exposed as a separate list mode | client.secrets.list(search=..., tags=..., secret_type=..., page=..., page_size=...) |
| Create, edit, or delete | Not exposed | Not exposed |
| Read history | Not exposed | Not exposed |
This reference covers JavaScript SDK 1.5.4 and Python SDK 0.2.3.
Keys and scope#
Keys can be up to 255 characters and are unique within their site or app scope. The API accepts any characters in a key.
Supplying an app selects that app's value first, then the site fallback when no
app value exists. Python uses the configured app_slug when the app argument
is omitted. JavaScript uses options.app only when it is supplied to the call.
Read-one options#
- App scope —
options.appin JavaScript,app=in Python. Selects the app's value, with the site value as the fallback. - Required tags —
options.tagsin JavaScript,tags=in Python. Returns not found when the resolved secret has none of the requested tags, matched by tag name.
The single-secret result contains key, tags, secret_type, and value.
JavaScript execute() retains the standard response wrapper and exposes the
secret in its data field. Python get() extracts and returns the secret object.
Batch options#
- Keys — The first
keysargument in JavaScript,keys=in Python. Comma-joined by the SDK; up to 100 keys. - App scope —
options.appin JavaScript,app=in Python. Applies app-over-site resolution. - Include metadata —
options.includeMetadatain JavaScript,include_metadata=in Python. Returns metadata objects instead of values only.
Both SDK list() methods retain the response wrapper, so the key map is in
data. Missing or sensitivity-denied keys are omitted. JavaScript 1.5.4 types
batch values as strings even though runtime values can also be JSON objects.
Python list filters#
When keys is absent, Python list() can browse and filter the readable
collection.
search— A partial key match.app— The app context. Defaults to the configuredapp_slug.tags— A list of tag slugs to filter by.secret_type— A secret-type slug to filter by.page— The page number. Defaults to1.page_size— Items per page. Defaults to20, clamped to1through100.
The wrapper contains status, message, and data. List responses also include
total; they do not emit a separate pagination object.
Error and disclosure behavior#
A read can fail with an authentication, permission, not-found, conflict, or
validation error. Each read endpoint treats public, private, and sensitive
values differently; see Security and limits
for who can read what, and how caching works.