Share a runbook with a team
Say an engineer has a script that refunds a Stripe payment, and the support team needs it several times a day. Today they ask in a channel and wait. Here’s how to give Support a form instead, without giving anyone the Stripe key.
1. Save the key as a secret
Section titled “1. Save the key as a secret”A workspace owner or admin saves it once. It can only ever be sent to
api.stripe.com:
printf %s "$STRIPE_KEY" | reminix secrets set STRIPE_KEY --hosts api.stripe.com2. Write the script
Section titled “2. Write the script”{ "slug": "refund-customer", "name": "Refund a customer", "description": "Refunds a Stripe payment in full.", "entry": "index.ts", "hosts": ["api.stripe.com"], "secrets": { "STRIPE_KEY": { "host": "api.stripe.com", "header": "Authorization", "value": "Bearer {secret}" } }, "inputSchema": { "type": "object", "required": ["paymentId", "reason"], "properties": { "paymentId": { "type": "string", "title": "Payment ID (pi_…)" }, "reason": { "type": "string", "title": "Reason", "enum": ["duplicate", "fraudulent", "requested_by_customer"] } } }}export default async function run( inputs: { paymentId: string; reason: string }, ctx,) { ctx.log(`refunding ${inputs.paymentId} (${inputs.reason})`); const res = await fetch("https://api.stripe.com/v1/refunds", { method: "POST", body: new URLSearchParams({ payment_intent: inputs.paymentId, reason: inputs.reason, }), }); const refund = await res.json(); if (!res.ok) throw new Error(refund.error?.message ?? "Stripe refused"); return { refund: refund.id, status: refund.status };}The input schema becomes the form: a text field for the payment and a list for the reason. Throwing an error makes the run fail with that message, so Support sees why.
3. Publish it
Section titled “3. Publish it”reminix scripts publish ./refund-customer --publish4. Share it with Support only
Section titled “4. Share it with Support only”On the script’s page, under Settings → Who can use it, choose Only these teams and pick Support. Through the API:
curl -X PATCH https://api.reminix.com/v1/scripts/refund-customer \ -H "Authorization: Bearer $REMINIX_TOKEN" -H "X-Workspace: acme" \ -H "Content-Type: application/json" \ -d '{ "access": "teams", "teamIds": ["<support team id>"] }'Support now sees Refund a customer under Scripts, fills in the form, and clicks Run. Everyone else doesn’t see it at all.
5. If agents should use it too
Section titled “5. If agents should use it too”Set Which runs need approval to Agents need approval. An agent can then start a refund, but it waits until an owner or admin approves it. See Give your agents safe tools.
Every refund is on record, with who ran it, the inputs and Stripe’s answer, on the script’s page.
Related: Scripts, Secrets, Governance.