Skip to main content
MysteryBox is now called SecretStash. The Nebius AI Cloud CLI, API and Terraform provider still use the mysterybox service identifier. Keep using mysterybox in scripts and manifests.
Each secret can have multiple versions. Versions are useful when you need to change credentials or update a secret payload without modifying existing references, such as configurations, scripts or services that point to the specific secret. For more information, see About SecretStash.

Prerequisites

Make sure you are in a group that has at least the editor role within your tenant or project; for example, the default editors group. You can check this in the Administration → IAM section of the web console.
Creating a secret or a version of a secret does not automatically grant you access to view payloads in that secret or version. The editor role is enough to create a secret or a version, but viewing payloads requires the mysterybox.payload-viewer role, which is a sub-role of admin but not editor.

How to create a version

  1. In the web console, go to  Cryptography → SecretStash.
  2. Locate the required secret and then click Create version.
  3. (Optional) On the page that opens, add a version description. For example, “New database password.”
  4. Update Key and Value. These fields display the key-value pair created in the original version. You can reuse an existing key and value, or you can update them. If you update Value, select a data type for it:
    • Text: Specify a plain string. Commonly used for passwords, tokens and API keys.
    • File: Upload a binary file. Convenient for certificates, private keys and configuration files.
  5. (Optional) To store multiple key-value pairs in a single version, click Add pair. Then, specify additional key-value pairs.
  6. If you want this version to become primary (it will be returned by default when the secret is referenced), keep the Make this version primary option enabled.
  7. Click Create version.
After the version is created, you can pin requests to it.