doctl secrets create
Generated on 3 Aug 2026
from doctl version
v1.166.0
Usage
doctl secrets create <name> [flags]Aliases
cDescription
Creates a secret container in the specified region and stores key-value pairs inside it.
If no --value or --from-env-file flags are provided, key-value pairs are read interactively with –interactive. You are prompted for each key, then each value is masked.
Example
The following example creates a secret with key-value pairs:
doctl secrets create my-secret --region nyc3 --value key=@./value.txt --value other-key=-Flags
| Option | Description |
|---|---|
--format |
Columns for output in a comma-separated list. Possible values: Name, Region, Version. |
--from-env-file |
Path to an env file containing key-value pairs to store in the secret. |
--help, -h |
Help for this command |
--no-header |
Return raw data with no headers Default: false |
--region |
Region where the secret is stored. If omitted, you are prompted when running with –interactive. |
--value |
Key-value pair in key=value format (repeatable). Values may be read from a file with key=@path or from stdin with key=-. If omitted, keys and masked values are read with –interactive. |
Related Commands
| Command | Description |
|---|---|
| doctl secrets | Display commands to manage Secrets Manager |
Global Flags
| Option | Description |
|---|---|
--access-token, -t |
API V2 access token |
--api-url, -u |
Override default API endpoint |
--config, -c |
Specify a custom config file Default: |
--context |
Specify a custom authentication context name |
--http-retry-max |
Set maximum number of retries for requests that fail with a 429 or 500-level error
Default: 5 |
--http-retry-wait-max |
Set the minimum number of seconds to wait before retrying a failed request
Default: 30 |
--http-retry-wait-min |
Set the maximum number of seconds to wait before retrying a failed request
Default: 1 |
--interactive |
Enable interactive behavior. Defaults to true if the terminal supports it (default false)
Default: false |
--output, -o |
Desired output format [text|json] Default: text |
--trace |
Show a log of network activity while performing a command Default: false |
--verbose, -v |
Enable verbose output Default: false |