Skip to content
>devspeak
← glossary
level 1Understanding Your Project

Secret

also: secrets, api key, api keys, secret key

A private value, like a password or API key, that proves your app is allowed to use a service. Anyone who has it can act as your app.

a bit more technical

Sensitive credentials such as API keys, database passwords, private keys and signing keys. Secrets belong in environment variables or a secret manager, never in the repository or in code sent to the browser, and must be replaced (rotated) if exposed.

picture it

A secret is the key to your shop. Whoever holds a copy can walk in, take stock and lock you out. You don't tape it to the front door.

why it matters

Agents handle secrets constantly when connecting to payments, email and AI services. A secret pasted into code or shared publicly can leak, and leaked keys get abused fast, sometimes costing real money.

what your agent might say
agent
Your OpenAI key is written directly in api.ts. That's a secret, so I'll move it to an environment variable and make sure .env isn't committed.
how you might use it
you → your agent
Never put secrets in the code or the frontend. Load them from environment variables and tell me which ones I need to set.
common mistake

Thinking a secret is safe once you delete it from the code. If it was ever saved in the repository's history or shared publicly, treat it as leaked and replace it.

builds on