Skip to content
Thyme Docs

Secrets

Tasks read secrets as strings through ctx.secrets. Check required keys explicitly and avoid putting credentials in args, source, logs, or persistent storage.

const apiKey = ctx.secrets.PRICE_API_KEY
if (!apiKey) throw new Error('PRICE_API_KEY is required')

Local development

The CLI loads project .env values and then task-local functions/<task>/.env overrides. These files are not uploaded. Only loaded configuration values that survive filtering become task secrets; do not assume every variable in your shell is exposed to task code.

The local runtime removes THYME_API_URL, THYME_AUTH_TOKEN, RPC_URL, and SIMULATE_ACCOUNT, plus unsafe keys __proto__, constructor, and prototype.

Commit .env.example to describe required keys and keep actual .env files ignored.

Cloud project secrets

Create secrets in Console → Secrets or through the authorized management API. Values are stored in the secret vault; the console and API return redacted metadata rather than revealing stored values. Secret keys must match ^[A-Za-z_][A-Za-z0-9_]*$.

The cloud reserves RPC_URL, TASK_ARGS, and THYME_SECRETS_JSON. Prefer application-specific names such as PRICE_API_KEY rather than runtime-looking names.

Bind a secret to each executable that needs it. Creating a project secret alone does not make it visible to all tasks. The runtime resolves bound values at invocation and exposes them through ctx.secrets.

Rotation and deletion

Rotation replaces the stored value without changing the binding; later runs receive the new value. Remove all executable bindings before deleting a secret. A running invocation may already have resolved its values, so rotation does not rewrite its environment.

Flow redacts known secret values from captured logs, but transformed, encoded, or partial secret material may not match a redaction pattern. Log decisions and identifiers, not credentials.

See secret operations for the console workflow and storage for non-secret state.