Secrets
Keep the API keys and tokens agents' tools need, by name, and release them only to signed-in machines.
Agents' tools often need a credential: a tracker's service token, a model provider's API key. Instead of each person pasting it into their machine, you keep it once in the console, by the name the tool expects. A machine asks for the secrets a project may use when a session starts. For tools, the workbench's gate holds the value and the agent is given a stand-in, never the value itself. Once a value is in, nobody can read it back from the console.
Where secrets are kept
| Kept by | Who manages it | Where |
|---|---|---|
| Your organisation | Administrators | Secrets |
| One of your teams | Administrators | Secrets |
| A project | The project's owners | The project's Policy tab |
| One repository of a project | The project's owners | The project's Policy tab |
Anyone on a project sees the names and facts of the secrets it may use, never the values. When two secrets share a name, the most specific one wins: a repository's over the project's, the project's over a team's or the organisation's.
In Mojo Up AI Cloud, a team's owners and admins act as its administrators.
Add a secret
Open the page
For the organisation or a team, open Secrets. For a project or one of its repositories, open the project and its Policy tab. Choose Add a secret.
Describe it
- Name, as the tool expects it, for example
TRACKER_TOKEN. - Value: sealed on the way in, never shown again.
- Kept by: your organisation, your team, this project or this repository.
- What it is for: a sentence people will see.
- Remind us to rotate it after (days): optional. Past that age, the secret is marked Due for rotation.
Say what may use it
Under Used by, tick one or more:
| Use | Who holds the value |
|---|---|
| Tools | The workbench's gate holds it; the agent never sees it. |
| A model provider | The inference proxy holds it. Name the provider, for example anthropic. |
| The agent's environment | The agent can read it. The only use that exposes the value to the agent. |
Keep it
Choose Keep it. Machines get it at their next ask.
Rotate, disable or remove
Beside each secret you manage:
- Rotate asks for a new value, seals it, and raises the secret's version. Machines get the new value at their next ask.
- Disable keeps the secret but releases it to nobody; Enable brings it back.
- Remove deletes it. Machines lose it at their next ask.
Who gets a secret
A machine asks for the secrets one project (and one of its repositories) may use. It gets them only when:
- it is signed in to your organisation;
- the person it works for is a member of the project (a node names that person, and must name the secrets it needs);
- the secret is not disabled.
Every release is one entry in the audit trail, naming the secrets, their versions and scopes, never a value.
In the workbench
People can keep secrets on their own machine too, under Settings, Secrets in AI Workbench, which also shows what each repository asks for and what the organisation provides.