Mojo UpDocs
Administration

Secrets

Keep the API keys and tokens agents' tools need, by name, and release them only to signed-in machines.

Agents' tools often need a credential: a tracker's service token, a model provider's API key. Instead of each person pasting it into their machine, you keep it once in the console, by the name the tool expects. A machine asks for the secrets a project may use when a session starts. For tools, the workbench's gate holds the value and the agent is given a stand-in, never the value itself. Once a value is in, nobody can read it back from the console.

Where secrets are kept

Kept byWho manages itWhere
Your organisationAdministratorsSecrets
One of your teamsAdministratorsSecrets
A projectThe project's ownersThe project's Policy tab
One repository of a projectThe project's ownersThe project's Policy tab

Anyone on a project sees the names and facts of the secrets it may use, never the values. When two secrets share a name, the most specific one wins: a repository's over the project's, the project's over a team's or the organisation's.

In Mojo Up AI Cloud, a team's owners and admins act as its administrators.

Add a secret

Open the page

For the organisation or a team, open Secrets. For a project or one of its repositories, open the project and its Policy tab. Choose Add a secret.

Describe it

  • Name, as the tool expects it, for example TRACKER_TOKEN.
  • Value: sealed on the way in, never shown again.
  • Kept by: your organisation, your team, this project or this repository.
  • What it is for: a sentence people will see.
  • Remind us to rotate it after (days): optional. Past that age, the secret is marked Due for rotation.

Say what may use it

Under Used by, tick one or more:

UseWho holds the value
ToolsThe workbench's gate holds it; the agent never sees it.
A model providerThe inference proxy holds it. Name the provider, for example anthropic.
The agent's environmentThe agent can read it. The only use that exposes the value to the agent.

Keep it

Choose Keep it. Machines get it at their next ask.

Rotate, disable or remove

Beside each secret you manage:

  • Rotate asks for a new value, seals it, and raises the secret's version. Machines get the new value at their next ask.
  • Disable keeps the secret but releases it to nobody; Enable brings it back.
  • Remove deletes it. Machines lose it at their next ask.

Who gets a secret

A machine asks for the secrets one project (and one of its repositories) may use. It gets them only when:

  • it is signed in to your organisation;
  • the person it works for is a member of the project (a node names that person, and must name the secrets it needs);
  • the secret is not disabled.

Every release is one entry in the audit trail, naming the secrets, their versions and scopes, never a value.

In the workbench

People can keep secrets on their own machine too, under Settings, Secrets in AI Workbench, which also shows what each repository asks for and what the organisation provides.

On this page