--- title: "Delete secret" description: "How to delete a secret using an Infisical Token scoped to a project and environment" --- Prerequisites: - Set up and add envars to [Infisical Cloud](https://app.infisical.com). - Create either an [API Key](/api-reference/overview/authentication) or [Infisical Token](/documentation/platform/token) for your project and environment with write access enabled. - Grasp a basic understanding of the system and its underlying cryptography [here](/api-reference/overview/introduction). - [Ensure that your project is blind-indexed](../blind-indices). ## Example ```js const axios = require('axios'); const BASE_URL = 'https://app.infisical.com'; const deleteSecrets = async () => { const serviceToken = 'your_service_token'; const secretType = 'shared' // 'shared' or 'personal' const secretKey = 'some_key' // 1. Get your Infisical Token data const { data: serviceTokenData } = await axios.get( `${BASE_URL}/api/v2/service-token`, { headers: { Authorization: `Bearer ${serviceToken}` } } ); // 2. Delete secret from Infisical await axios.delete( `${BASE_URL}/api/v3/secrets/${secretKey}`, { workspaceId: serviceTokenData.workspace, environment: serviceTokenData.environment, type: secretType }, { headers: { Authorization: `Bearer ${serviceToken}` }, } ); }; deleteSecrets(); ``` ```Python import requests BASE_URL = "https://app.infisical.com" def delete_secrets(): service_token = "" secret_type = "shared" # "shared" or "personal" secret_key = "some_key" # 1. Get your Infisical Token data service_token_data = requests.get( f"{BASE_URL}/api/v2/service-token", headers={"Authorization": f"Bearer {service_token}"}, ).json() # 2. Delete secret from Infisical requests.delete( f"{BASE_URL}/api/v2/secrets/{secret_key}", json={ "workspaceId": service_token_data["workspace"], "environment": service_token_data["environment"], "type": secret_type }, headers={"Authorization": f"Bearer {service_token}"}, ) delete_secrets() ``` If using an `API_KEY` to authenticate with the Infisical API, then you should include it in the `X_API_KEY` header.