Skip to content

Secrets and environment

A pack's code needs two kinds of values, and Kindgi keeps them apart:

  • Secrets a tool uses for a tenant: an API key, a signing key. A tool declares them by name, and Kindgi resolves them for each call from the tenant's secrets (ctx.secrets). Model providers, HTTP tools, MCP endpoints and webhooks name theirs the same way.
  • Your code's own environment: a service URL, a database your app owns, a feature flag. Your code reads them from process.env or os.environ, and the pack declares which ones it needs.

On your machine, kindgi dev keeps both in the pack's env files. In a deployment, secrets live in the runtime's secrets store, and the pack service gets the environment the pack declares.

Give a tool a secret shows the tool's side.