> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orgo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply secrets

> Apply selected vault secrets to an existing Linux computer.

Send `{"names":["ANTHROPIC_API_KEY"]}` to apply those names from your vault to a running Linux computer. `names` takes 1 to 50 environment variable names made of letters, digits, and underscores, not starting with a digit, up to 64 characters each. Duplicates are ignored. Workspace values take precedence over account values. This requires write access to the computer's workspace.

The response contains `success`, `names`, `restart_required: true`, and a `message`. The values are written to `/root/.orgo-secrets.env`, which `/root/.env`, `.bashrc`, and `.profile` load. Open a new terminal or restart the agent to load the updated environment. Existing processes keep their current environment. Applications using their own credential files may need to be configured separately.

An invalid `names` list returns `400`. A missing secret returns `404` with `{ "error": "A requested secret is not available in your vault for this workspace." }`. A computer that is not running returns `409`; a different operating system returns `422`. A failure to write the values on the computer returns `502` with `{ "error": "Could not apply secrets. Check the computer connection and try again." }`. A missing or invalid API key returns `401`. An unknown computer returns `404` with `{ "error": "Desktop not found" }`. No access to the computer's workspace, view-only access, or an API key scoped to another workspace returns `403`. A trial computer whose trial has ended returns `402` with `{ "error": "Choose a plan to continue." }`. If Orgo cannot verify the credential because of a server-side fault, such as a database outage, the request returns `503` with `{ "error": "Service temporarily unavailable. …" }` and `Retry-After: 5`. Retry after that delay; do not rotate the key. Secret values are never included in the response.

Saving or deleting a vault entry does not automatically change computers already running. Deleting a vault entry also does not erase a copy previously installed on a computer.


## OpenAPI

````yaml POST /computers/{id}/secrets/sync
openapi: 3.1.0
info:
  title: Orgo API
  description: >-
    Launch cloud computers that AI agents can control and interact with. Create
    workspaces, provision computers, and control them programmatically.
  version: 2.0.0
  contact:
    name: Orgo Support
    email: spencer@orgo.ai
    url: https://orgo.ai
servers:
  - url: https://www.orgo.ai/api
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Account
    description: >-
      Account capacity: how many computers an account may run, and adding or
      giving back more.
  - name: Clients
    description: >-
      Run Orgo for your clients from your own app: a workspace and scoped key
      each, billed to you or to them.
  - name: Workspaces
    description: Organize computers into named workspaces
  - name: Computers
    description: Provision and manage virtual computers
  - name: Computer Lifecycle
    description: Start, stop, and restart computers
  - name: Computer Actions
    description: Control mouse, keyboard, and execute commands
  - name: Screens
    description: >-
      More than one desktop on a single computer. Each screen is its own X
      server with its own cursor and window manager, so an agent working on one
      cannot disturb another.
  - name: Files
    description: Upload and download files
  - name: Templates
    description: Author, build, and launch reproducible computers from templates
paths:
  /computers/{id}/secrets/sync:
    post:
      tags:
        - Computers
      summary: Apply secrets to a computer
      description: >-
        Applies the named vault secrets to a running Linux computer by writing
        them to `/root/.orgo-secrets.env`. Workspace values take precedence over
        account values. Open a new terminal or restart the agent to load them.
        Values are never returned.
      operationId: applyComputerSecrets
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
          description: Computer UUID or instance ID.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - names
              properties:
                names:
                  type: array
                  minItems: 1
                  maxItems: 50
                  items:
                    type: string
                    pattern: ^[A-Za-z_][A-Za-z0-9_]{0,63}$
                    description: >-
                      An environment variable name: letters, digits, and
                      underscores, not starting with a digit, up to 64
                      characters.
            example:
              names:
                - ANTHROPIC_API_KEY
      responses:
        '200':
          description: >-
            Secrets applied to a running Linux computer. Open a new terminal or
            restart its agent to read the new environment. Values are never
            returned.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  names:
                    type: array
                    items:
                      type: string
                  restart_required:
                    type: boolean
                  message:
                    type: string
        '400':
          description: '`names` is not a list of 1 to 50 valid environment variable names.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: >-
                  names must contain 1-50 environment variable names (letters,
                  numbers, underscores; no leading number).
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/TrialInactive'
        '403':
          $ref: '#/components/responses/AccessDenied'
        '404':
          description: >-
            No computer with this id, or a requested secret is not in your vault
            for this workspace.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                no-computer:
                  summary: Unknown computer
                  value:
                    error: Desktop not found
                no-secret:
                  summary: Missing secret
                  value:
                    error: >-
                      A requested secret is not available in your vault for this
                      workspace.
        '409':
          description: The computer is not running.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Start the computer before applying secrets.
        '422':
          description: The computer is not a Linux computer.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Applying secrets currently requires a Linux computer.
        '502':
          description: The values could not be written on the computer.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: >-
                  Could not apply secrets. Check the computer connection and try
                  again.
        '503':
          $ref: '#/components/responses/AuthUnavailable'
components:
  schemas:
    Error:
      type: object
      description: >-
        The base error body. Every failure carries `error`; individual endpoints
        add the fields named in the schemas below.
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable message.
          example: Access denied
        code:
          type: string
          description: >-
            Machine-readable reason. Present on the failures that define one,
            absent otherwise.
  responses:
    Unauthorized:
      description: 'No usable credential. Send `Authorization: Bearer $ORGO_API_KEY`.'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            invalid-key:
              summary: The key is not one of yours
              value:
                error: Invalid API key
            no-credential:
              summary: No key and no session
              value:
                error: Authentication required
    TrialInactive:
      description: >-
        The computer is a free trial computer whose trial is no longer active,
        or it is paid for by its own subscription or dedicated purchase and that
        payment has lapsed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            trial:
              summary: Trial no longer active
              value:
                error: Choose a plan to continue.
            payment:
              summary: The computer's own payment has lapsed
              value:
                error: Manage this computer’s payment in Account → Usage.
    AccessDenied:
      description: >-
        You are not the owner or a member of the computer's workspace, you have
        view-only access, or the API key is scoped to another workspace.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            no-access:
              summary: Not the owner or a member of the workspace
              value:
                error: You do not have access to this workspace.
            view-only:
              summary: View-only member, and the request changes something
              value:
                error: >-
                  This workspace is view-only. Ask the owner for write access
                  (workspace_read_only).
            scope-mismatch:
              summary: The API key is scoped to another workspace
              value:
                error: >-
                  This API key cannot access this workspace
                  (workspace_scope_mismatch).
    AuthUnavailable:
      description: >-
        Orgo could not verify the credential because of a server-side fault,
        such as a database outage. Retry after `Retry-After`. Do not rotate the
        key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: >-
              Service temporarily unavailable. The database is not accepting
              requests. Retry shortly.
      headers:
        Retry-After:
          description: Seconds to wait before retrying. Always `5`.
          schema:
            type: string
            example: '5'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key authentication. Get your key at orgo.ai/workspaces

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.