doctl secrets update

Generated on 3 Aug 2026 from doctl version v1.166.0

Usage

doctl secrets update <name> [flags]

Description

Replaces all key-value pairs in a secret with a new version.

This removes any keys not included in the update. Use secrets set to add or change keys, or secrets unset to remove keys. Pass --replace to confirm full replacement.

Example

The following example replaces a secret:

doctl secrets update my-secret --region nyc3 --replace --value key=@./value.txt --value other-key=value

Flags

Option Description
--force, -f Replace the secret without prompting when keys would be removed.
Default: false
--format Columns for output in a comma-separated list. Possible values: Name, Region, Version.
--from-env-file Path to an env file containing key-value pairs to store in the secret.
--help, -h Help for this command
--no-header Return raw data with no headers
Default: false
--region Region where the secret is stored. If omitted, you are prompted when running with –interactive.
--replace Replace the entire secret. Required to perform a full replacement.
Default: false
--value Key-value pair in key=value format (repeatable). Values may be read from a file with key=@path or from stdin with key=-. If omitted, keys and masked values are read with –interactive.
Command Description
doctl secrets Display commands to manage Secrets Manager

Global Flags

Option Description
--access-token, -t API V2 access token
--api-url, -u Override default API endpoint
--config, -c Specify a custom config file
Default:
    --context Specify a custom authentication context name
    --http-retry-max Set maximum number of retries for requests that fail with a 429 or 500-level error
    Default: 5
    --http-retry-wait-max Set the minimum number of seconds to wait before retrying a failed request
    Default: 30
    --http-retry-wait-min Set the maximum number of seconds to wait before retrying a failed request
    Default: 1
    --interactive Enable interactive behavior. Defaults to true if the terminal supports it (default false)
    Default: false
    --output, -o Desired output format [text|json]
    Default: text
    --trace Show a log of network activity while performing a command
    Default: false
    --verbose, -v Enable verbose output
    Default: false

    We can't find any results for your search.

    Try using different keywords or simplifying your search terms.