Skip to content
Thyme Docs

Manage Secrets

Open Console → Secrets in the intended project. Owners and admins can create and rotate values; the list returns metadata and status rather than plaintext secrets. The management API supports authorized secret operations as well.

Create and bind

  1. Choose an application-specific key, such as PRICE_API_KEY.
  2. Enter the value and save it. Secret names match ^[A-Za-z_][A-Za-z0-9_]*$.
  3. In the executable's secret settings, bind the new secret.
  4. Read it as ctx.secrets.PRICE_API_KEY and report a clear error if missing.

The cloud reserves RPC_URL, TASK_ARGS, and THYME_SECRETS_JSON. Local runtime filtering is different; see secrets.

Rotate

Replace the value using the rotate action. Existing bindings keep the same secret ID and later invocations resolve the new version. An invocation that has already loaded its environment can continue using the old value.

Remove

Unbind the secret from every executable first, then delete it. Deletion is blocked while references remain. If the upstream credential was compromised, revoke it with its issuing service as well; deleting a Flow record does not revoke an external provider's token.

Use log redaction as a safeguard, and avoid logging any secret or derived credential. Keep sensitive values out of persistent storage.