Secrets
A secret is a sensitive value: a database password, an API key, an integration token. It goes in once and does not come out.
The screen never shows the value
The interface has no way to read a secret — not even for an organization administrator. This is not a permission limit someone could loosen: it is a property of the storage. The value is protected at the moment it is written.
The screen says so out loud precisely so nobody goes looking for a reveal button.
What the screen shows
| Column | Content |
|---|---|
| Name | The key the application reads |
| Scope | Organization, project, or environment |
| Last changed | When the value was last written |
Declaring
- Open the project and go to Secrets.
- Choose the scope.
- Enter the name and the value.
- Save.
The same three scopes as variables apply here, with the same rule: the most specific one wins.
Editing means replacing
There is no "view and adjust". If you do not remember the value, you write a new one. The previous version stays in the history as a fact — the date and author of the change — never as recoverable text.
Rotating a credential
- Generate the new credential in the source system.
- Write the new value into the secret, replacing the previous one.
- Deploy so the application starts using it.
- Revoke the old credential in the source system.
Doing step 4 before step 3 takes the application down: until the deployment, it is still using the old value.
When it takes effect
On the next deployment, like all configuration. The screen warns when a change has been declared and not yet applied.
What never becomes a secret
A secret is for the value, not for the address. A service URL, a queue name, and a project identifier are variables: hiding them protects nothing and makes diagnosis harder, because they stop appearing on the configuration screens.
Where secrets never appear
Secrets are automatically stripped from everything the platform shows or stores: build logs, application logs, error messages, and failure evidence. A credential that accidentally shows up in a tool's output is masked before being stored — preserving the surrounding context, because a fully masked line solves the leak and creates a useless log.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.