Secrets
A secret is an environment variable whose value Hiraiship never shows again once it's saved: not in the dashboard, not through the API, not to anyone in your workspace. Use it for passwords, API keys and tokens.
How secrets behave
- Write-only. After saving, the dashboard shows that the key is set, never its value. To change it, enter a new one.
- Same value check without the value. For a secret set in several environments, the dashboard still tells you whether the value is the same everywhere, without revealing it.
- Encrypted at rest, each environment with its own key. A copy of Hiraiship's database alone reveals nothing.
- Given to your app like any variable. Secret or not, your code reads it the same way; see Reading variables.
Turning a variable into a secret
A plain variable can be marked secret at any time. The reverse is refused: turning a secret back into a plain variable would reveal its value. Delete it and add it again instead.
Keep secrets out of the browser
A secret is only safe while it stays on the server. Never put one in a frontend build command or anywhere a bundle can pick it up: everything a browser downloads is public.