# Using the beta update Secrets API endpoint

**URL:** <https://community.doppler.com/t/using-the-beta-update-secrets-api-endpoint/1084>\
**Category:** Need Help\
**Created:** [April 11, 2023, 3:24pm UTC](https://community.doppler.com/t/using-the-beta-update-secrets-api-endpoint/1084 "2023-04-11T15:24:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![went](https://avatars.discourse-cdn.com/v4/letter/w/ac91a4/32.png) [@went](https://community.doppler.com/u/went)\
**Post date:** [April 11, 2023, 3:24pm UTC](https://community.doppler.com/t/using-the-beta-update-secrets-api-endpoint/1084/1 "2023-04-11T15:24:13Z")

</div>

Hello community. I’m wondering if anyone has had success using the beta update Secrets API endpoint?

Below is a sample of how my request is structured.

```auto
curl --request POST \
     --url https://api.doppler.com/v3/configs/config/secrets \
     --header 'accept: application/json' \
     --header 'authorization: Bearer my_service_key' \
     --header 'content-type: application/json' \
     --data '
{
  "project": "my_project_name",
  "config": "my_config_name",
  "secrets": {
    "my_secret_name: "my_secret_value"
  }
}
'

```

After sending the request I receive a `400 Bad Request` and the following response.

```auto
{
    "messages": [
        "Either secrets or change_requests must be specified"
    ],
    "success": false
}

```

There is a section in the API documentation that states:

> The `change_requests` parameter is a new parameter that is an array whose elements are objects matching the following format. This endpoint must receive either a `secrets` or `change_requests` parameter (but not both).

I’ve not had success structuring my request to successfully update a secret. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![went](https://avatars.discourse-cdn.com/v4/letter/w/ac91a4/32.png) [@went](https://community.doppler.com/u/went)\
**Post date:** [April 27, 2023, 7:29pm UTC](https://community.doppler.com/t/using-the-beta-update-secrets-api-endpoint/1084/2 "2023-04-27T19:29:45Z")

</div>

You will experience this error using Postman if you’re excluding the `Content-Length` generated header in your request.  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/doppler/original/1X/ed9c1708b06a0ada5545eff0cabddbb17d345d74.png)
