doctl secrets update
Generated on 3 Aug 2026
from doctl version
v1.166.0
Usage
doctl secrets update <name> [flags]Description
Replaces all key-value pairs in a secret with a new version.
This removes any keys not included in the update. Use secrets set to add or change keys, or secrets unset to remove keys. Pass --replace to confirm full replacement.
Example
The following example replaces a secret:
doctl secrets update my-secret --region nyc3 --replace --value key=@./value.txt --value other-key=valueFlags
| Option | Description |
|---|---|
--force, -f |
Replace the secret without prompting when keys would be removed. Default: false |
--format |
Columns for output in a comma-separated list. Possible values: Name, Region, Version. |
--from-env-file |
Path to an env file containing key-value pairs to store in the secret. |
--help, -h |
Help for this command |
--no-header |
Return raw data with no headers Default: false |
--region |
Region where the secret is stored. If omitted, you are prompted when running with –interactive. |
--replace |
Replace the entire secret. Required to perform a full replacement. Default: false |
--value |
Key-value pair in key=value format (repeatable). Values may be read from a file with key=@path or from stdin with key=-. If omitted, keys and masked values are read with –interactive. |
Related Commands
| Command | Description |
|---|---|
| doctl secrets | Display commands to manage Secrets Manager |
Global Flags
| Option | Description |
|---|---|
--access-token, -t |
API V2 access token |
--api-url, -u |
Override default API endpoint |
--config, -c |
Specify a custom config file Default: |
--context |
Specify a custom authentication context name |
--http-retry-max |
Set maximum number of retries for requests that fail with a 429 or 500-level error
Default: 5 |
--http-retry-wait-max |
Set the minimum number of seconds to wait before retrying a failed request
Default: 30 |
--http-retry-wait-min |
Set the maximum number of seconds to wait before retrying a failed request
Default: 1 |
--interactive |
Enable interactive behavior. Defaults to true if the terminal supports it (default false)
Default: false |
--output, -o |
Desired output format [text|json] Default: text |
--trace |
Show a log of network activity while performing a command Default: false |
--verbose, -v |
Enable verbose output Default: false |