Secrets and environment
A pack's code needs two kinds of values, and Kindgi keeps them apart:
- Secrets a tool uses for a tenant: an API key, a signing key. A tool
declares them by name, and Kindgi resolves them for each call from the
tenant's secrets (
ctx.secrets). Model providers, HTTP tools, MCP endpoints and webhooks name theirs the same way. - Your code's own environment: a service URL, a database your app owns,
a feature flag. Your code reads them from
process.envoros.environ, and the pack declares which ones it needs.
On your machine, kindgi dev keeps both in the pack's env files. In a
deployment, secrets live in the runtime's secrets store, and the pack
service gets the environment the pack declares.
- Keep local values in env files: what
kindgi devreads, and what reaches your code. - Store a secret:
kindgi secrets, its environments and scopes. - Declare the environment your code reads:
env.requiredandenv.optional. - Set values per environment: the pack service's
environment in staging or production, and
kindgi env plan.
Give a tool a secret shows the tool's side.