Skip to content

Secrets

A secret is an API key or token your scripts use, such as a Stripe key or a Slack token. Reminix keeps it so the code never has to.

  • Write-only. You save a value, and nothing shows it again: not the app, the API, the command line or an agent. To rotate it, save a new value.
  • Encrypted at rest, with a key for each workspace.
  • Sent only to its hosts. Each secret lists the hosts it may be sent to, such as api.stripe.com. Reminix attaches it to a script’s requests to those hosts, and to nothing else, whatever the code says.
  • Not readable by code, unless you turn on “Let scripts read the value itself” for that secret.

Owners and admins save, rotate and delete secrets. Members see their names and hosts, which they need to write manifests, but never their values.

In the app, go to Settings → Secrets → Add secret. On the command line, the value comes from standard input, never from an argument, which would end up in your shell history:

Terminal window
printf %s "$STRIPE_KEY" | reminix secrets set STRIPE_KEY --hosts api.stripe.com

Through the API, with a key that has secrets:write:

Terminal window
curl -X PUT https://api.reminix.com/v1/secrets/STRIPE_KEY \
-H "Authorization: Bearer $REMINIX_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "value": "sk_live_…", "hosts": ["api.stripe.com"] }'

GET /v1/secrets lists names and hosts, and DELETE /v1/secrets/{name} deletes one. Agents can list secrets but never save or delete them. An agent that needs a secret asks you to add it.

A script declares the secrets it uses in its reminix.json. See Scripts → Calling APIs. A run uses a secret only if the secret allows the host it’s sent to. After a rotation, the next run uses the new value.