Project secrets
Last reviewed:
Secrets store service keys and sensitive settings encrypted. The owner can add, edit, reveal, and delete them. Editors can see the masked list of names but cannot reveal or change values.
Adding a secret
- 1
Open “Secrets”
In the project workspace, click “+”, then “Secrets”. Wait for the list to load. Contact support if secret storage is unavailable.
- 2
Enter the name and value
Under “Add a new secret”, enter the name your app expects. Start with an uppercase Latin letter, followed by uppercase letters, numbers, or underscores, up to 128 characters. Paste the value into its field; do not send it as a chat message.
- 3
Save and wait
Click “Add secret”. Wait for the form to clear and the name to appear masked in the list. Reusing an existing name updates its value. A value is required, with a limit of 32,768 characters; follow the message if it is rejected.
- 4
Check its use
Tell Codey only the secret’s name and purpose. Reopen preview after saving and redeploy for the published website to use the new value. If a task is running, wait for it to finish before retrying the save.
Editing or revealing a value
- 1
Choose the secret
Click the pencil beside its name. The current value loads into the edit form, and the name is locked while editing.
- 2
Save the new value
Replace the value and click “Save changes”. Wait for saving to finish. Cancel editing if you do not want a change. On failure, check owner access and wait for active tasks to finish before retrying.
- 3
Reveal only when needed
The eye icon reveals an ordinary secret only on the owner’s explicit request. Click “Hide” when finished. Input fields and revealed values can be visible on your screen; avoid including them in screenshots.
Deleting a secret
- 1
Check whether the app needs it
Check that the app no longer needs the key, or prepare a replacement. Removing it can stop the feature that uses it.
- 2
Click the delete icon
In “Secrets”, click the trash icon beside the name. Deletion starts immediately without a confirmation dialog. Wait for the name to disappear.
- 3
Check removal and revoke the key if needed
Reopen preview. If the name remains in the list, wait for active tasks to finish and reopen it as the owner. To revoke the key, use the service account that issued it; deleting a secret here does not do that.
Deleting a secret removes it from the project list. It does not guarantee removal of a value previously injected into the published website, even after redeployment. Contact support to remove it from the published website’s settings, and revoke the key in its service account if it should no longer work.
Automatic injection and hidden values
Secrets are supplied automatically when preview and deployment start, so the app does not need literal values in its files. Saving or deleting a secret may stop preview to refresh its environment. Shared-project previews use test values to protect secrets; see Your database.
- The ordinary list shows the name, update time, and a fixed mask, revealing neither the value nor its length.
- The managed database connection does not appear in this list and cannot be revealed or deleted using ordinary secret controls.
- Codey receives needed secret names, not values, from the secret list. Use the dedicated field instead of pasting secrets into chat.
- Do not ask Codey to print values in code or logs. Encrypted storage cannot prevent an app from exposing values it prints itself.
When Codey requests a secret in chat
- 1
Use the input card
When the secret request card appears, read its name and description. Paste the value in the card’s masked field, not the chat message box.
- 2
Save it directly
Click “Save” and wait for secure-save confirmation. The value goes to secret storage without being added to chat text, and the field is cleared. Use “Replace” to change it.
- 3
Handle a rejected save
If the project workspace is busy, wait for the task to finish and save again. Do not send the value as a chat message to work around the error.