Workspace secrets
Store API keys, credentials, and other sensitive values as workspace secrets — referenced in apps without exposing them in code.
Workspace secrets
Workspace secrets are encrypted key-value pairs stored at the workspace level and shared across apps. They're the secure way to store API keys, tokens, and credentials.
Why use workspace secrets?
Without secrets, sensitive values like API keys are stored inline in your app's configuration — visible to all workspace members and potentially logged.
With workspace secrets:
- Values are encrypted at rest using AES-256
- Values are never shown in plaintext after saving (write-only)
- Secrets can be referenced by name across multiple apps
- Access is controlled by workspace role
Creating a secret
- Workspace Settings → Secrets → New secret
- Enter a name (e.g.
STRIPE_SECRET_KEY,SENDGRID_API_KEY) - Enter the value (e.g. the actual API key)
- Click Save
The value is encrypted immediately. You won't be able to view it again — only overwrite it.
Using a secret in an app
Reference the secret in your app by name using the {{secret.SECRET_NAME}} syntax in:
- Integration configuration fields
- Webhook headers
- Custom script injection
Or ask the AI:
"Use the workspace secret STRIPE_SECRET_KEY for the Stripe integration"
Per-app secrets
In addition to workspace secrets, each app has its own App Secrets in App Settings → Advanced → Secrets. These work identically but are scoped to a single app.
Use workspace secrets when the same credential is shared across multiple apps. Use app secrets for app-specific keys.
Secret access by role
| Role | Can view names | Can read values | Can create/edit |
|---|---|---|---|
| Owner | ✓ | ✗ (write-only) | ✓ |
| Admin | ✓ | ✗ (write-only) | ✓ |
| Developer | ✓ | ✗ | ✗ |
| Viewer | ✗ | ✗ | ✗ |
Secret rotation
To rotate a secret (e.g. after a credential leak):
- Update the secret value with the new key
- The updated value is used immediately across all referencing apps — no redeployment needed
