{
  "openapi": "3.0.3",
  "info": {
    "title": "sondahub Google Secret Manager sandbox",
    "version": "0.14.2",
    "description": "An independent imitation of Google Cloud Secret Manager’s v1 REST API for testing, run by sondahub — not affiliated with or endorsed by Google. No Google Cloud project is involved.\n\nAuth: any bearer token. The client libraries get one by signing a JWT with the service account in https://api.sondahub.com/sandbox/google-secret-manager/service-account.json (sandbox@sondahub-demo.iam.gserviceaccount.com; its key is published) and exchanging it at https://api.sondahub.com/sandbox/google-secret-manager/token — or they send a self-signed JWT straight away; both work. Use the libraries’ REST transport: a Cloudflare worker can’t serve native gRPC.\n\nResource names come back with the project number, as Google writes them. Errors are google.rpc.Status. Writes live in the X-Sondahub-Session token each answer carries: send the newest one back as a header and the next request sees what you made; without it every request starts from the seed project. More at https://sondahub.com/sandboxes/google-secret-manager/",
    "contact": {
      "name": "sondahub",
      "url": "https://sondahub.com/sandboxes/google-secret-manager/"
    }
  },
  "externalDocs": {
    "description": "The sandbox, in full",
    "url": "https://sondahub.com/sandboxes/google-secret-manager/"
  },
  "servers": [
    {
      "url": "https://api.sondahub.com"
    }
  ],
  "security": [
    {
      "bearer": []
    }
  ],
  "tags": [
    {
      "name": "Secrets",
      "description": "Secrets: global (with replication) or regional (under /locations/{location})."
    },
    {
      "name": "Versions",
      "description": "Versions: numbered, ENABLED, DISABLED or DESTROYED."
    },
    {
      "name": "IAM",
      "description": "A secret’s IAM policy."
    },
    {
      "name": "Locations",
      "description": "Where regional secrets can live."
    },
    {
      "name": "Sign-in",
      "description": "OAuth 2.0 for the published service account."
    }
  ],
  "paths": {
    "/v1/projects/{project}/secrets": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Create a secret",
        "operationId": "CreateSecret",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secretId",
            "in": "query",
            "required": false,
            "description": "The new secret’s id: letters, digits, _ and -.",
            "schema": {
              "type": "string"
            },
            "example": "my-secret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          },
          "409": {
            "$ref": "#/components/responses/E409"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "replication": {
                    "type": "object",
                    "description": "{\"automatic\": {}} or {\"userManaged\": {\"replicas\": [{\"location\": \"us-east1\"}]}} — required for a global secret.",
                    "example": {
                      "automatic": {}
                    }
                  },
                  "labels": {
                    "type": "object",
                    "description": "Up to 64.",
                    "example": {
                      "env": "dev"
                    }
                  },
                  "annotations": {
                    "type": "object",
                    "description": "Free-form, up to 16 KiB."
                  },
                  "topics": {
                    "type": "array",
                    "description": "Pub/Sub topics for notifications (needed with rotation).",
                    "items": {}
                  },
                  "expireTime": {
                    "type": "string",
                    "description": "When it deletes itself (or ttl)."
                  },
                  "ttl": {
                    "type": "string",
                    "description": "Seconds, like \"86400s\"."
                  },
                  "rotation": {
                    "type": "object",
                    "description": "nextRotationTime and rotationPeriod."
                  },
                  "versionDestroyTtl": {
                    "type": "string",
                    "description": "Delay destruction by this long (at least 86400s)."
                  }
                },
                "example": {
                  "replication": {
                    "automatic": {}
                  },
                  "labels": {
                    "env": "dev"
                  }
                }
              },
              "example": {
                "replication": {
                  "automatic": {}
                },
                "labels": {
                  "env": "dev"
                }
              }
            }
          }
        }
      },
      "get": {
        "tags": [
          "Secrets"
        ],
        "summary": "List secrets",
        "operationId": "ListSecrets",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "pageSize",
            "in": "query",
            "required": false,
            "description": "Up to 25000.",
            "schema": {
              "type": "integer"
            },
            "example": 25
          },
          {
            "name": "pageToken",
            "in": "query",
            "required": false,
            "description": "From nextPageToken.",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "filter",
            "in": "query",
            "required": false,
            "description": "name:…, labels.<key>=…, labels.<key>:*, create_time>…, state:ENABLED (versions); AND, OR, NOT, -.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}": {
      "get": {
        "tags": [
          "Secrets"
        ],
        "summary": "Get a secret",
        "operationId": "GetSecret",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "db-password"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      },
      "patch": {
        "tags": [
          "Secrets"
        ],
        "summary": "Update a secret",
        "operationId": "UpdateSecret",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          },
          {
            "name": "updateMask",
            "in": "query",
            "required": false,
            "description": "The fields to change: labels, annotations, topics, expire_time, ttl, rotation, version_aliases, version_destroy_ttl.",
            "schema": {
              "type": "string"
            },
            "example": "labels"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          },
          "409": {
            "$ref": "#/components/responses/E409"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "labels": {
                    "type": "object",
                    "description": "With updateMask=labels."
                  },
                  "etag": {
                    "type": "string",
                    "description": "Fail with ABORTED if it changed since you read it."
                  }
                },
                "example": {
                  "labels": {
                    "env": "staging",
                    "owner": "web-team"
                  }
                }
              },
              "example": {
                "labels": {
                  "env": "staging",
                  "owner": "web-team"
                }
              }
            }
          }
        }
      },
      "delete": {
        "tags": [
          "Secrets"
        ],
        "summary": "Delete a secret",
        "operationId": "DeleteSecret",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          },
          {
            "name": "etag",
            "in": "query",
            "required": false,
            "description": "Only if it still has this etag.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          },
          "409": {
            "$ref": "#/components/responses/E409"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}:addVersion": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "Add a version",
        "operationId": "AddSecretVersion",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "payload": {
                    "type": "object",
                    "description": "data (base64, up to 64 KiB) and optionally dataCrc32c, which is checked.",
                    "example": {
                      "data": "aGVsbG8gd29ybGQ=",
                      "dataCrc32c": "3381945770"
                    }
                  }
                },
                "required": [
                  "payload"
                ],
                "example": {
                  "payload": {
                    "data": "aGVsbG8gd29ybGQ=",
                    "dataCrc32c": "3381945770"
                  }
                }
              },
              "example": {
                "payload": {
                  "data": "aGVsbG8gd29ybGQ=",
                  "dataCrc32c": "3381945770"
                }
              }
            }
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions": {
      "get": {
        "tags": [
          "Versions"
        ],
        "summary": "List versions",
        "operationId": "ListSecretVersions",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "stripe-api-key"
          },
          {
            "name": "pageSize",
            "in": "query",
            "required": false,
            "description": "Up to 25000.",
            "schema": {
              "type": "integer"
            },
            "example": 25
          },
          {
            "name": "pageToken",
            "in": "query",
            "required": false,
            "description": "From nextPageToken.",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "filter",
            "in": "query",
            "required": false,
            "description": "name:…, labels.<key>=…, labels.<key>:*, create_time>…, state:ENABLED (versions); AND, OR, NOT, -.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions/{version}": {
      "get": {
        "tags": [
          "Versions"
        ],
        "summary": "Get a version",
        "operationId": "GetSecretVersion",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "stripe-api-key"
          },
          {
            "name": "version",
            "in": "path",
            "required": true,
            "description": "A version number, latest, or an alias.",
            "schema": {
              "type": "string"
            },
            "example": "latest"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions/{version}:access": {
      "get": {
        "tags": [
          "Versions"
        ],
        "summary": "Access a version’s payload",
        "operationId": "AccessSecretVersion",
        "description": "payload.data (base64) and payload.dataCrc32c. A disabled or destroyed version answers FAILED_PRECONDITION.",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "stripe-api-key"
          },
          {
            "name": "version",
            "in": "path",
            "required": true,
            "description": "A version number, latest, or an alias.",
            "schema": {
              "type": "string"
            },
            "example": "latest"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions/{version}:disable": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "Disable a version",
        "operationId": "DisableSecretVersion",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "db-password"
          },
          {
            "name": "version",
            "in": "path",
            "required": true,
            "description": "A version number, latest, or an alias.",
            "schema": {
              "type": "string"
            },
            "example": "1"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "etag": {
                    "type": "string",
                    "description": "Only if the version still has this etag."
                  }
                },
                "example": {}
              },
              "example": {}
            }
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions/{version}:enable": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "Enable a version",
        "operationId": "EnableSecretVersion",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "db-password"
          },
          {
            "name": "version",
            "in": "path",
            "required": true,
            "description": "A version number, latest, or an alias.",
            "schema": {
              "type": "string"
            },
            "example": "1"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "etag": {
                    "type": "string",
                    "description": "Only if the version still has this etag."
                  }
                },
                "example": {}
              },
              "example": {}
            }
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}/versions/{version}:destroy": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "Destroy a version",
        "operationId": "DestroySecretVersion",
        "description": "With versionDestroyTtl on the secret, the version is disabled now and destroyed when the TTL runs out (enable cancels it).",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "db-password"
          },
          {
            "name": "version",
            "in": "path",
            "required": true,
            "description": "A version number, latest, or an alias.",
            "schema": {
              "type": "string"
            },
            "example": "1"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "etag": {
                    "type": "string",
                    "description": "Only if the version still has this etag."
                  }
                },
                "example": {}
              },
              "example": {}
            }
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}:getIamPolicy": {
      "get": {
        "tags": [
          "IAM"
        ],
        "summary": "Get the IAM policy",
        "operationId": "GetIamPolicy",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}:setIamPolicy": {
      "post": {
        "tags": [
          "IAM"
        ],
        "summary": "Set the IAM policy",
        "operationId": "SetIamPolicy",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          },
          "409": {
            "$ref": "#/components/responses/E409"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "policy": {
                    "type": "object",
                    "description": "bindings: [{role, members}]."
                  }
                },
                "example": {
                  "policy": {
                    "bindings": [
                      {
                        "role": "roles/secretmanager.secretAccessor",
                        "members": [
                          "serviceAccount:sandbox@sondahub-demo.iam.gserviceaccount.com"
                        ]
                      }
                    ]
                  }
                }
              },
              "example": {
                "policy": {
                  "bindings": [
                    {
                      "role": "roles/secretmanager.secretAccessor",
                      "members": [
                        "serviceAccount:sandbox@sondahub-demo.iam.gserviceaccount.com"
                      ]
                    }
                  ]
                }
              }
            }
          }
        }
      }
    },
    "/v1/projects/{project}/secrets/{secret}:testIamPermissions": {
      "post": {
        "tags": [
          "IAM"
        ],
        "summary": "Test permissions",
        "operationId": "TestIamPermissions",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "secret",
            "in": "path",
            "required": true,
            "description": "The secret id.",
            "schema": {
              "type": "string"
            },
            "example": "api-config"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "permissions": {
                    "type": "array",
                    "description": "Permission names.",
                    "items": {}
                  }
                },
                "example": {
                  "permissions": [
                    "secretmanager.versions.access",
                    "secretmanager.secrets.delete"
                  ]
                }
              },
              "example": {
                "permissions": [
                  "secretmanager.versions.access",
                  "secretmanager.secrets.delete"
                ]
              }
            }
          }
        }
      }
    },
    "/v1/projects/{project}/locations": {
      "get": {
        "tags": [
          "Locations"
        ],
        "summary": "List locations",
        "operationId": "ListLocations",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/v1/projects/{project}/locations/{location}/secrets": {
      "get": {
        "tags": [
          "Locations"
        ],
        "summary": "List a location’s regional secrets",
        "operationId": "ListRegionalSecrets",
        "description": "Every secret and version path above works under /locations/{location}/ too, for regional secrets (which have no replication policy).",
        "parameters": [
          {
            "name": "project",
            "in": "path",
            "required": true,
            "description": "Any project id (or number): the seed answers in every project.",
            "schema": {
              "type": "string"
            },
            "example": "sondahub-demo"
          },
          {
            "name": "location",
            "in": "path",
            "required": true,
            "description": "The location.",
            "schema": {
              "type": "string"
            },
            "example": "us-central1"
          },
          {
            "name": "pageSize",
            "in": "query",
            "required": false,
            "description": "Up to 25000.",
            "schema": {
              "type": "integer"
            },
            "example": 25
          },
          {
            "name": "pageToken",
            "in": "query",
            "required": false,
            "description": "From nextPageToken.",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "filter",
            "in": "query",
            "required": false,
            "description": "name:…, labels.<key>=…, labels.<key>:*, create_time>…, state:ENABLED (versions); AND, OR, NOT, -.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/sandbox/google-secret-manager/token": {
      "post": {
        "tags": [
          "Sign-in"
        ],
        "summary": "Exchange a signed JWT for an access token",
        "operationId": "Token",
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "properties": {
                  "grant_type": {
                    "type": "string",
                    "description": "urn:ietf:params:oauth:grant-type:jwt-bearer (or refresh_token)."
                  },
                  "assertion": {
                    "type": "string",
                    "description": "A JWT signed with the service account’s key."
                  }
                },
                "required": [
                  "grant_type"
                ],
                "example": {
                  "grant_type": "urn:ietf:params:oauth:grant-type:jwt-bearer",
                  "assertion": "<JWT>"
                }
              },
              "example": {
                "grant_type": "urn:ietf:params:oauth:grant-type:jwt-bearer",
                "assertion": "<JWT>"
              }
            }
          }
        }
      }
    },
    "/sandbox/google-secret-manager/service-account.json": {
      "get": {
        "tags": [
          "Sign-in"
        ],
        "summary": "The published service account key file",
        "operationId": "ServiceAccount",
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": []
      }
    }
  },
  "components": {
    "securitySchemes": {
      "bearer": {
        "type": "http",
        "scheme": "bearer",
        "description": "Any token, or one from the token endpoint."
      }
    },
    "responses": {
      "E400": {
        "description": "INVALID_ARGUMENT or FAILED_PRECONDITION.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "error": {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "integer"
                    },
                    "message": {
                      "type": "string"
                    },
                    "status": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      },
      "E401": {
        "description": "UNAUTHENTICATED: no bearer token.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "error": {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "integer"
                    },
                    "message": {
                      "type": "string"
                    },
                    "status": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      },
      "E404": {
        "description": "NOT_FOUND.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "error": {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "integer"
                    },
                    "message": {
                      "type": "string"
                    },
                    "status": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      },
      "E409": {
        "description": "ALREADY_EXISTS, or ABORTED for an etag that changed.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "error": {
                  "type": "object",
                  "properties": {
                    "code": {
                      "type": "integer"
                    },
                    "message": {
                      "type": "string"
                    },
                    "status": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}