diff --git a/docs/mint.json b/docs/mint.json
index 7b92d065e..3103bb59a 100644
--- a/docs/mint.json
+++ b/docs/mint.json
@@ -384,6 +384,7 @@
"pages": [
"sdks/languages/node",
"sdks/languages/python",
+ "sdks/languages/go",
"sdks/languages/java",
"sdks/languages/csharp"
]
diff --git a/docs/sdks/languages/go.mdx b/docs/sdks/languages/go.mdx
new file mode 100644
index 000000000..b6a308797
--- /dev/null
+++ b/docs/sdks/languages/go.mdx
@@ -0,0 +1,436 @@
+---
+title: "Infisical Go SDK"
+sidebarTitle: "Go"
+icon: "golang"
+---
+
+
+
+If you're working with Go Lang, the official [Infisical Go SDK](https://github.com/infisical/go-sdk) package is the easiest way to fetch and work with secrets for your application.
+
+- [Package](https://pkg.go.dev/github.com/infisical/go-sdk)
+- [Github Repository](https://github.com/infiscial/go-sdk)
+
+## Basic Usage
+
+```go
+import (
+ "fmt"
+ "os"
+
+ infisical "github.com/infisical/go-sdk"
+)
+
+func main() {
+
+ client, err := infisical.NewInfisicalClient(infisical.Config{
+ SiteUrl: "https://app.infisical.com", // Optional, default is https://app.infisical.com
+ })
+
+ if err != nil {
+ fmt.Printf("Error: %v", err)
+ os.Exit(1)
+ }
+
+ _, err = client.Auth().UniversalAuthLogin("YOUR_CLIENT_ID", "YOUR_CLIENT_SECRET")
+
+ if err != nil {
+ fmt.Printf("Authentication failed: %v", err)
+ os.Exit(1)
+ }
+
+ apiKeySecret, err := client.Secrets().Retrieve(infisical.RetrieveSecretOptions{
+ SecretKey: "API_KEY",
+ Environment: "dev",
+ ProjectID: "YOUR_PROJECT_ID",
+ SecretPath: "/",
+ })
+
+ if err != nil {
+ fmt.Printf("Error: %v", err)
+ os.Exit(1)
+ }
+
+ fmt.Printf("API Key Secret: %v", apiKeySecret)
+
+}
+```
+
+This example demonstrates how to use the Infisical Go SDK in a simple Go application. The application retrieves a secret named `API_KEY` from the `dev` environment of the `YOUR_PROJECT_ID` project.
+
+
+ We do not recommend hardcoding your [Machine Identity Tokens](/platform/identities/overview). Setting it as an environment variable would be best.
+
+
+# Installation
+
+```console
+$ go get github.com/infisical/go-sdk
+```
+# Configuration
+
+Import the SDK and create a client instance.
+
+```go
+client, err := infisical.NewInfisicalClient(infisical.Config{
+ SiteUrl: "https://app.infisical.com", // Optional, default is https://api.infisical.com
+ })
+
+if err != nil {
+ fmt.Printf("Error: %v", err)
+ os.Exit(1)
+}
+```
+
+### ClientSettings methods
+
+
+
+
+ The URL of the Infisical API. Default is `https://api.infisical.com`.
+
+
+
+ Optionally set the user agent that will be used for HTTP requests. _(Not recommended)_
+
+
+
+
+
+### Authentication
+
+The SDK supports a variety of authentication methods. The most common authentication method is Universal Auth, which uses a client ID and client secret to authenticate.
+
+#### Universal Auth
+
+**Using environment variables**
+
+Call `.Auth().UniversalAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` - Your machine identity client ID.
+- `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` - Your machine identity client secret.
+
+**Using the SDK directly**
+```go
+_, err := client.Auth().UniversalAuthLogin("CLIENT_ID", "CLIENT_SECRET")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+#### GCP ID Token Auth
+
+ Please note that this authentication method will only work if you're running your application on Google Cloud Platform.
+ Please [read more](/documentation/platform/identities/gcp-auth) about this authentication method.
+
+
+**Using environment variables**
+
+Call `.Auth().GcpIdTokenAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_GCP_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
+
+**Using the SDK directly**
+```go
+_, err := client.Auth().GcpIdTokenAuthLogin("YOUR_MACHINE_IDENTITY_ID")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+#### GCP IAM Auth
+
+**Using environment variables**
+
+Call `.Auth().GcpIamAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_GCP_IAM_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
+- `INFISICAL_GCP_IAM_SERVICE_ACCOUNT_KEY_FILE_PATH` - The path to your GCP service account key file.
+
+**Using the SDK directly**
+```go
+_, err = client.Auth().GcpIamAuthLogin("MACHINE_IDENTITY_ID", "SERVICE_ACCOUNT_KEY_FILE_PATH")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+#### AWS IAM Auth
+
+ Please note that this authentication method will only work if you're running your application on AWS.
+ Please [read more](/documentation/platform/identities/aws-auth) about this authentication method.
+
+
+**Using environment variables**
+
+Call `.Auth().AwsIamAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_AWS_IAM_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
+
+**Using the SDK directly**
+```go
+_, err = client.Auth().AwsIamAuthLogin("MACHINE_IDENTITY_ID")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+
+#### Azure Auth
+
+ Please note that this authentication method will only work if you're running your application on Azure.
+ Please [read more](/documentation/platform/identities/azure-auth) about this authentication method.
+
+
+**Using environment variables**
+
+Call `.Auth().AzureAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_AZURE_AUTH_IDENTITY_ID` - Your Infisical Machine Identity ID.
+
+**Using the SDK directly**
+```go
+_, err = client.Auth().AzureAuthLogin("MACHINE_IDENTITY_ID")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+#### Kubernetes Auth
+
+ Please note that this authentication method will only work if you're running your application on Kubernetes.
+ Please [read more](/documentation/platform/identities/kubernetes-auth) about this authentication method.
+
+
+**Using environment variables**
+
+Call `.Auth().KubernetesAuthLogin()` with empty arguments to use the following environment variables:
+
+- `INFISICAL_KUBERNETES_IDENTITY_ID` - Your Infisical Machine Identity ID.
+- `INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH_ENV_NAME` - The environment variable name that contains the path to the service account token. This is optional and will default to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
+
+**Using the SDK directly**
+```go
+// Service account token path will default to /var/run/secrets/kubernetes.io/serviceaccount/token if empty value is passed
+_, err = client.Auth().KubernetesAuthLogin("MACHINE_IDENTITY_ID", "SERVICE_ACCOUNT_TOKEN_PATH")
+
+if err != nil {
+ fmt.Println(err)
+ os.Exit(1)
+}
+```
+
+## Working with Secrets
+
+### client.Secrets().List(options)
+
+```go
+secrets, err := client.Secrets().List(infisical.ListSecretsOptions{
+ ProjectID: "PROJECT_ID",
+ Environment: "dev",
+ SecretPath: "/foo/bar",
+ AttachToProcessEnv: false,
+})
+```
+
+Retrieve all secrets within the Infisical project and environment that client is connected to
+
+#### Parameters
+
+
+
+
+ The slug name (dev, prod, etc) of the environment from where secrets should be fetched from.
+
+
+
+ The project ID where the secret lives in.
+
+
+
+ The path from where secrets should be fetched from.
+
+
+
+ Whether or not to set the fetched secrets to the process environment. If true, you can access the secrets like so `System.getenv("SECRET_NAME")`.
+
+
+
+ Whether or not to include imported secrets from the current path. Read about [secret import](/documentation/platform/secret-reference)
+
+
+
+ Whether or not to fetch secrets recursively from the specified path. Please note that there's a 20-depth limit for recursive fetching.
+
+
+
+ Whether or not to expand secret references in the fetched secrets. Read about [secret reference](/documentation/platform/secret-reference)
+
+
+
+
+
+### client.Secrets().Get(options)
+
+```go
+secret, err := client.Secrets().Retrieve(infisical.RetrieveSecretOptions{
+ SecretKey: "API_KEY",
+ ProjectID: "PROJECT_ID",
+ Environment: "dev",
+})
+```
+
+Retrieve a secret from Infisical.
+
+By default, `Secrets().Get()` fetches and returns a shared secret.
+
+#### Parameters
+
+
+
+
+ The key of the secret to retrieve.
+
+
+ The project ID where the secret lives in.
+
+
+ The slug name (dev, prod, etc) of the environment from where secrets should be fetched from.
+
+
+ The path from where secret should be fetched from.
+
+
+ The type of the secret. Valid options are "shared" or "personal". If not specified, the default value is "shared".
+
+
+
+
+### client.Secrets().Create(options)
+
+```go
+secret, err := client.Secrets().Create(infisical.CreateSecretOptions{
+ ProjectID: "PROJECT_ID",
+ Environment: "dev",
+
+ SecretKey: "NEW_SECRET_KEY",
+ SecretValue: "NEW_SECRET_VALUE",
+ SecretComment: "This is a new secret",
+})
+```
+
+Create a new secret in Infisical.
+
+#### Parameters
+
+
+
+
+ The key of the secret to create.
+
+
+ The value of the secret.
+
+
+ A comment for the secret.
+
+
+ The project ID where the secret lives in.
+
+
+ The slug name (dev, prod, etc) of the environment from where secrets should be fetched from.
+
+
+ The path from where secret should be created.
+
+
+ The type of the secret. Valid options are "shared" or "personal". If not specified, the default value is "shared".
+
+
+
+
+### client.Secrets().Update(options)
+
+```go
+secret, err := client.Secrets().Update(infisical.UpdateSecretOptions{
+ ProjectID: "PROJECT_ID",
+ Environment: "dev",
+ SecretKey: "NEW_SECRET_KEY",
+ NewSecretValue: "NEW_SECRET_VALUE",
+ NewSkipMultilineEncoding: false,
+})
+```
+
+Update an existing secret in Infisical.
+
+#### Parameters
+
+
+
+
+ The key of the secret to update.
+
+
+ The new value of the secret.
+
+
+ Whether or not to skip multiline encoding for the new secret value.
+
+
+ The project ID where the secret lives in.
+
+
+ The slug name (dev, prod, etc) of the environment from where secrets should be fetched from.
+
+
+ The path from where secret should be updated.
+
+
+ The type of the secret. Valid options are "shared" or "personal". If not specified, the default value is "shared".
+
+
+
+
+### client.Secrets().Delete(options)
+
+```go
+secret, err := client.Secrets().Delete(infisical.DeleteSecretOptions{
+ ProjectID: "PROJECT_ID",
+ Environment: "dev",
+ SecretKey: "SECRET_KEY",
+})
+```
+
+Delete a secret in Infisical.
+
+#### Parameters
+
+
+
+
+ The key of the secret to update.
+
+
+ The project ID where the secret lives in.
+
+
+ The slug name (dev, prod, etc) of the environment from where secrets should be fetched from.
+
+
+ The path from where secret should be deleted.
+
+
+ The type of the secret. Valid options are "shared" or "personal". If not specified, the default value is "shared".
+
+
+
\ No newline at end of file