# Conductor-csharp PutSecret adds extra quotes to secret values. Is this a bug?

**URL:** <https://community.orkes.io/t/conductor-csharp-putsecret-adds-extra-quotes-to-secret-values-is-this-a-bug/289>\
**Category:** Orkes Conductor\
**Tags:** orkes-conductor\
**Created:** [June 27, 2026, 4:43am UTC](https://community.orkes.io/t/conductor-csharp-putsecret-adds-extra-quotes-to-secret-values-is-this-a-bug/289 "2026-06-27T04:43:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_B](https://sea2.discourse-cdn.com/flex002/user_avatar/community.orkes.io/alex_b/32/151_2.png) [@Alex\_B](https://community.orkes.io/u/Alex_B)\
**Post date:** [June 27, 2026, 4:43am UTC](https://community.orkes.io/t/conductor-csharp-putsecret-adds-extra-quotes-to-secret-values-is-this-a-bug/289/1 "2026-06-27T04:43:52Z")

</div>

I’m using conductor-csharp (SecretResourceApi.PutSecret / PutSecretWithHttpInfo) and secrets are stored with extra quotes (e.g., **VERY SECRET** becomes " **VERY SECRET"** ), which makes them unusable for authentication.

In decompiled code, this line is used:

```auto
obj = ((body == null || !(body.GetType() != typeof(byte[]))) ? body : Configuration.ApiClient.Serialize(body));

```

For any non-null input, body is typed as string, so:  
• body == null is false  
• body.GetType() != typeof(byte[]) is true  
• !(true) is false  
• condition becomes false || false =\> false

So it always takes the Serialize(body) branch for string, which appears to force quote-wrapping.

Has anyone found a way to use this specific method without that behavior, or confirmed this as an SDK bug?

---

<div class="post-metadata">

**Author:** ![nthmost](https://sea2.discourse-cdn.com/flex002/user_avatar/community.orkes.io/nthmost/32/81_2.png) [@nthmost](https://community.orkes.io/u/nthmost)\
**Post date:** [July 29, 2026, 9:51am UTC](https://community.orkes.io/t/conductor-csharp-putsecret-adds-extra-quotes-to-secret-values-is-this-a-bug/289/2 "2026-07-29T09:51:49Z")

</div>

Hi there – i’ve confirmed this is a SDK bug in conductor-oss/csharp-sdk (issue #165 ([SecretResourceApi.PutSecret serializes string body as JSON, storing secrets with extra quotes · Issue #165 · conductor-oss/csharp-sdk · GitHub](https://github.com/conductor-oss/csharp-sdk/issues/165))).

Workaround until fixed — call the endpoint directly, bypassing the SDK’s serialization:

var client = new HttpClient();  
client.DefaultRequestHeaders.Add(“X-Authorization”, yourToken);  
var content = new StringContent(“VERY SECRET”, Encoding.UTF8, “text/plain”);  
await client.PutAsync(“[https://your-conductor-server/api/secrets/MY\_KEY](https://your-conductor-server/api/secrets/MY_KEY)”, content);

If you’re willing and able, please add any supporting info directly to the github issue so we can keep things together. Thanks!
