Secrets
A secret is an API key or token your capabilities use — a Stripe key, a Slack token. Reminix keeps it so the code never has to:
- Write-only. You save a value; nothing — the app, the API, the command line, an agent — ever shows it again. Rotate it by saving a new value.
- Encrypted at rest, with a key per workspace.
- Sent only to its hosts. Each secret lists the hosts it may be sent
to (
api.stripe.com). Reminix attaches it to a capability’s requests to those hosts — and to nothing else, whatever the code says. - Not readable by code, unless you turn on “Let capabilities read the value itself” for that secret.
Owners and admins save, rotate and delete secrets. Members see their names and hosts (to write manifests), never their values.
Saving one
Section titled “Saving one”In the app: Settings → Secrets → Add secret. From the command line, the value comes from standard input — never an argument, which would land in your shell history:
printf %s "$STRIPE_KEY" | reminix secrets set STRIPE_KEY --hosts api.stripe.comThrough the API, with a key holding secrets:write:
curl -X PUT https://api.reminix.com/v1/secrets/STRIPE_KEY \ -H "Authorization: Bearer $REMINIX_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "value": "sk_live_…", "hosts": ["api.stripe.com"] }'GET /v1/secrets lists names and hosts; DELETE /v1/secrets/{name}
deletes one. Agents can list secrets but never save or delete them —
an agent that needs a secret asks you to add it.
Using one
Section titled “Using one”A capability declares the secrets it uses in its reminix.json — see
Capabilities → Calling APIs. A run
uses a secret only if the secret allows the host it is sent to; saving a
new value (rotation) reaches the next run.