Skip to content

Store a secret

Tools' declared secrets, HTTP tools' credentials, model providers' keys and MCP endpoints' credentials are all secrets of your tenant, looked up by name in an environment. kindgi secrets stores them without the value ever going through your shell's history or a command line.

Terminal window
pnpm exec kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenant
Value:
Re-enter to confirm:

It prompts twice, without echoing. In a script, pipe the value in with --from-stdin, or read it from a file only you can read with --from-file=<path> (a file others can read is refused):

Terminal window
openssl rand -hex 32 | tr -d '\n' | kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenant --from-stdin
Set RECEIPT_SIGNING_KEY at tenant in local.
  • --env is the environment the secret belongs to. A runtime resolves secrets in the environment it serves (KINDGI_ENV); kindgi dev serves local.
  • --scope is where it lives: tenant, org:<orgId> or project:<projectId>. It's required.

The secret is available to the next call. Nothing restarts.

set refuses a name that exists:

Version conflict: RECEIPT_SIGNING_KEY already exists (version 1). To store a new version, retry with --write-mode=add-version.

Write a new value with --write-mode=add-version:

Terminal window
openssl rand -hex 32 | tr -d '\n' | kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenant --from-stdin --write-mode=add-version

--if-version=<n> makes the write conditional: it fails if someone changed the secret since version n.

list and get show names and versions, never values:

Terminal window
kindgi secrets get RECEIPT_SIGNING_KEY --env=local --scope=tenant
{
"name": "RECEIPT_SIGNING_KEY",
"scope": {
"kind": "tenant",
"tenantId": "bb22c936-5111-429a-bfce-09650af85492"
},
"envName": "local",
"currentVersion": 1,
"createdAt": "1970-01-01T00:00:00.000Z",
"updatedAt": "1970-01-01T00:00:00.000Z"
}

kindgi secrets list --env=local --scope=tenant lists every secret in the environment.

kindgi dev's secrets store is the pack's env files (Keep local values in env files), so it behaves like them:

  • set writes the value to .env.local, readable only by you.
  • Every name in the env files is a secret of local, and list shows them all. Their timestamps are the epoch, as above.
  • A name has one value: replacing it with add-version overwrites it, and its version stays 1.
  • The files are the same for every scope, so --scope doesn't separate anything here.
  • There's nothing to rotate or revoke. Those commands say so:
Error [server]: Dev secrets live in your env files (.env, .env.local) and have no versions to rotate. Edit the value there, or run `kindgi secrets set RECEIPT_SIGNING_KEY --write-mode=add-version`.
Error [server]: Dev secrets live in your env files (.env, .env.local) and have no revocation. Remove HTTPBIN_TOKEN from those files.

Versions, scopes, rotation and revocation are what a deployment's secrets store (KINDGI_SECRETS_BACKEND=postgres, see the environment variable reference) adds. Every flag is in the kindgi secrets reference.