Store a secret
Tools' declared secrets, HTTP tools' credentials, model providers' keys and
MCP endpoints' credentials are all secrets of your tenant, looked up by name
in an environment. kindgi secrets stores them without the value ever
going through your shell's history or a command line.
Set one
Section titled “Set one”pnpm exec kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenantnpx --yes @kindgi/cli@0.1 secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenantValue:Re-enter to confirm:It prompts twice, without echoing. In a script, pipe the value in with
--from-stdin, or read it from a file only you can read with
--from-file=<path> (a file others can read is refused):
openssl rand -hex 32 | tr -d '\n' | kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenant --from-stdin Set RECEIPT_SIGNING_KEY at tenant in local.--envis the environment the secret belongs to. A runtime resolves secrets in the environment it serves (KINDGI_ENV);kindgi devserveslocal.--scopeis where it lives:tenant,org:<orgId>orproject:<projectId>. It's required.
The secret is available to the next call. Nothing restarts.
Replace one
Section titled “Replace one”set refuses a name that exists:
Version conflict: RECEIPT_SIGNING_KEY already exists (version 1). To store a new version, retry with --write-mode=add-version.Write a new value with --write-mode=add-version:
openssl rand -hex 32 | tr -d '\n' | kindgi secrets set RECEIPT_SIGNING_KEY --env=local --scope=tenant --from-stdin --write-mode=add-version--if-version=<n> makes the write conditional: it fails if someone changed
the secret since version n.
List them
Section titled “List them”list and get show names and versions, never values:
kindgi secrets get RECEIPT_SIGNING_KEY --env=local --scope=tenant{ "name": "RECEIPT_SIGNING_KEY", "scope": { "kind": "tenant", "tenantId": "bb22c936-5111-429a-bfce-09650af85492" }, "envName": "local", "currentVersion": 1, "createdAt": "1970-01-01T00:00:00.000Z", "updatedAt": "1970-01-01T00:00:00.000Z"}kindgi secrets list --env=local --scope=tenant lists every secret in the
environment.
Under kindgi dev
Section titled “Under kindgi dev”kindgi dev's secrets store is the pack's env files
(Keep local values in env files), so it behaves like them:
setwrites the value to.env.local, readable only by you.- Every name in the env files is a secret of
local, andlistshows them all. Their timestamps are the epoch, as above. - A name has one value: replacing it with
add-versionoverwrites it, and its version stays 1. - The files are the same for every scope, so
--scopedoesn't separate anything here. - There's nothing to rotate or revoke. Those commands say so:
Error [server]: Dev secrets live in your env files (.env, .env.local) and have no versions to rotate. Edit the value there, or run `kindgi secrets set RECEIPT_SIGNING_KEY --write-mode=add-version`.Error [server]: Dev secrets live in your env files (.env, .env.local) and have no revocation. Remove HTTPBIN_TOKEN from those files.Versions, scopes, rotation and revocation are what a deployment's secrets
store (KINDGI_SECRETS_BACKEND=postgres, see the
environment variable reference)
adds. Every flag is in the kindgi secrets reference.