Secrets
A secret is an API key or token your scripts use, such as a Stripe key or a Slack token. Reminix keeps it so the code never has to.
- Write-only. You save a value, and nothing shows it again: not the app, the API, the command line or an agent. To rotate it, save a new value.
- Encrypted at rest, with a key for each workspace.
- Sent only to its hosts. Each secret lists the hosts it may be sent
to, such as
api.stripe.com. Reminix attaches it to a script’s requests to those hosts, and to nothing else, whatever the code says. - Not readable by code, unless you turn on “Let scripts read the value itself” for that secret.
Owners and admins save, rotate and delete secrets. Members see their names and hosts, which they need to write manifests, but never their values.
Saving one
Section titled “Saving one”In the app, go to Settings → Secrets → Add secret. On the command line, the value comes from standard input, never from an argument, which would end up in your shell history:
printf %s "$STRIPE_KEY" | reminix secrets set STRIPE_KEY --hosts api.stripe.comThrough the API, with a key that has secrets:write:
curl -X PUT https://api.reminix.com/v1/secrets/STRIPE_KEY \ -H "Authorization: Bearer $REMINIX_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "value": "sk_live_…", "hosts": ["api.stripe.com"] }'GET /v1/secrets lists names and hosts, and
DELETE /v1/secrets/{name} deletes one. Agents can list secrets but
never save or delete them. An agent that needs a secret asks you to add
it.
Using one
Section titled “Using one”A script declares the secrets it uses in its reminix.json. See
Scripts → Calling APIs. A run
uses a secret only if the secret allows the host it’s sent to. After a rotation, the next run uses the new value.