> ## Documentation Index
> Fetch the complete documentation index at: https://docs.airctrl.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an encrypted record

> Stores ciphertext and encrypted keys prepared by the client. AIRCTRL does not receive the plaintext secret. Requires records:create.



## OpenAPI

````yaml /api-reference/openapi.json post /records
openapi: 3.0.0
info:
  title: AIRCTRL API
  description: >-
    Programmatic access to AIRCTRL. Record values are encrypted by the client,
    so the API stores ciphertext and encrypted keys instead of plaintext record
    values.
  version: '1'
  contact: {}
servers:
  - url: https://api.airctrl.dev/v1
    description: Production
security: []
tags:
  - name: Context
    description: Find the accounts available to the caller.
  - name: Projects
    description: Create and manage projects.
  - name: Records
    description: Store and use client-encrypted records.
  - name: Audit
    description: Read record activity and access history.
  - name: Providers
    description: Discover supported AI providers.
  - name: Provider Credentials
    description: Manage encrypted provider credentials.
  - name: Gateways
    description: Create and operate AI gateways.
  - name: Usage
    description: Read gateway usage and spend data.
  - name: Service Accounts
    description: Read Service Account metadata and grant records.
paths:
  /records:
    post:
      tags:
        - Records
      summary: Create an encrypted record
      description: >-
        Stores ciphertext and encrypted keys prepared by the client. AIRCTRL
        does not receive the plaintext secret. Requires records:create.
      operationId: RecordsController_create
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateRecordDto'
      responses:
        '201':
          description: Record created.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    enum:
                      - true
                  data:
                    $ref: '#/components/schemas/RecordCreated'
                required:
                  - ok
                  - data
                additionalProperties: false
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - personal-access-token: []
components:
  schemas:
    CreateRecordDto:
      type: object
      properties:
        accountId:
          type: string
          format: uuid
          description: Account that owns the project.
        projectId:
          type: string
          format: uuid
          description: Project where the record will be created.
        name:
          type: string
          description: Record name.
        tags:
          type: array
          items:
            type: string
          description: Searchable labels.
        ciphertext:
          type: string
          description: Client-encrypted secret value.
        cipherMeta:
          type: object
          additionalProperties: true
          description: Client-generated encryption metadata.
        wrappedDek:
          type: object
          additionalProperties: true
          description: Encrypted record key. AIRCTRL stores it without opening it.
        projectWrappedDek:
          type: object
          additionalProperties: true
          description: Optional record key encrypted for the project key.
        secretFormat:
          type: string
          enum:
            - plain
            - json
            - env
            - password
            - api_key
            - database
            - ssh
            - certificate
            - oauth_client
            - cloud_iam
            - service_account
            - webhook
            - license
            - totp
        secretDueAt:
          type: string
          format: date-time
          description: Optional review or expiration time.
          nullable: true
        rotationIntervalDays:
          type: integer
          minimum: 1
          nullable: true
      additionalProperties: false
      required:
        - accountId
        - projectId
        - name
        - tags
        - ciphertext
        - cipherMeta
        - wrappedDek
        - secretFormat
    RecordCreated:
      type: object
      properties:
        recordId:
          type: string
          format: uuid
      additionalProperties: false
      required:
        - recordId
    ErrorEnvelope:
      type: object
      properties:
        ok:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable error category.
            message:
              type: string
              description: Plain-language reason for the failure.
            details:
              description: Optional validation or error details.
          additionalProperties: false
          required:
            - code
            - message
        requestId:
          type: string
          description: Request identifier to include when contacting support.
      additionalProperties: false
      required:
        - ok
        - error
      description: Standard AIRCTRL error response.
  responses:
    BadRequest:
      description: >-
        The request is invalid. Check the body, query parameters and
        identifiers.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: bad_request
              message: Request validation failed
              details:
                - Check the submitted values.
            requestId: req_example
    Unauthorized:
      description: >-
        The token is missing, invalid, expired or cannot authenticate this
        request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: unauthorized
              message: Authentication is required
            requestId: req_example
    Forbidden:
      description: >-
        The authenticated principal does not have the required permission or
        resource access.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: forbidden
              message: not_authorized
            requestId: req_example
    Conflict:
      description: >-
        The request conflicts with the current resource state or reuses an
        idempotency key incorrectly.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: conflict
              message: idempotency_key_reused_with_different_params
            requestId: req_example
    RateLimited:
      description: The caller exceeded the API request limit. Wait before retrying.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: rate_limited
              message: Too many requests
            requestId: req_example
    InternalError:
      description: >-
        AIRCTRL could not complete the request. Retry later and keep the request
        ID for support.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            ok: false
            error:
              code: internal_error
              message: Internal server error
            requestId: req_example
  securitySchemes:
    personal-access-token:
      scheme: bearer
      bearerFormat: JWT
      type: http
      description: Human personal access token (`sk-actrl-pat-...`).

````