Skip to content

Secrets

A secret is an API key or token your capabilities use — a Stripe key, a Slack token. Reminix keeps it so the code never has to:

  • Write-only. You save a value; nothing — the app, the API, the command line, an agent — ever shows it again. Rotate it by saving a new value.
  • Encrypted at rest, with a key per workspace.
  • Sent only to its hosts. Each secret lists the hosts it may be sent to (api.stripe.com). Reminix attaches it to a capability’s requests to those hosts — and to nothing else, whatever the code says.
  • Not readable by code, unless you turn on “Let capabilities read the value itself” for that secret.

Owners and admins save, rotate and delete secrets. Members see their names and hosts (to write manifests), never their values.

In the app: Settings → Secrets → Add secret. From the command line, the value comes from standard input — never an argument, which would land in your shell history:

Terminal window
printf %s "$STRIPE_KEY" | reminix secrets set STRIPE_KEY --hosts api.stripe.com

Through the API, with a key holding secrets:write:

Terminal window
curl -X PUT https://api.reminix.com/v1/secrets/STRIPE_KEY \
-H "Authorization: Bearer $REMINIX_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "value": "sk_live_…", "hosts": ["api.stripe.com"] }'

GET /v1/secrets lists names and hosts; DELETE /v1/secrets/{name} deletes one. Agents can list secrets but never save or delete them — an agent that needs a secret asks you to add it.

A capability declares the secrets it uses in its reminix.json — see Capabilities → Calling APIs. A run uses a secret only if the secret allows the host it is sent to; saving a new value (rotation) reaches the next run.