Secrets

API keys and passwords your apps use, which no agent or log ever sees.

Built on gitleaks

Plans: Every plan, including the free app

What you get

  • Values set by people, never by agents
  • Write-only: no screen or command shows a value again
  • Every version kept, with rollback
  • Values removed from logs
  • A record of each delivery to a running app
  • Shared by every app, or kept to one

How it works

An app's whisk.yaml lists the names of the secrets it needs. A person pastes each value into the dashboard, and the app receives it as an environment variable when it starts. Whisk's API never returns a value, and an agent that tries to set one is refused.

Each value is encrypted with a key that belongs to the business before it is stored. Every change creates a version that can be rolled back, and values are removed from the app's logs.

Before a push is stored, gitleaks, the open-source secret scanner, checks it for keys pasted into code. A push holding one is refused, as described under secret scanning.

Example

A hardware wholesaler's order app needs a key for its freight carrier's API. The agent declares the name and sends the office manager a link, and she pastes the key into the dashboard. When the carrier issues a new key, she replaces it and the app restarts with the new value.

For your coding agent

secrets: [CARRIER_API_KEY]

whisk secrets set CARRIER_API_KEY prints a link where a person pastes the value; the command never takes the value itself. The whisk.yaml reference covers the secrets list.

All features