Secrets
API keys and passwords your apps use, which no agent or log ever sees.
Built on gitleaks
Plans: Every plan, including the free app
What you get
- Values set by people, never by agents
- Write-only: no screen or command shows a value again
- Every version kept, with rollback
- Values removed from logs
- A record of each delivery to a running app
- Shared by every app, or kept to one
How it works
An app's whisk.yaml lists the names of the secrets it needs. A person pastes each value into the dashboard, and the app receives it as an environment variable when it starts. Whisk's API never returns a value, and an agent that tries to set one is refused.
Each value is encrypted with a key that belongs to the business before it is stored. Every change creates a version that can be rolled back, and values are removed from the app's logs.
Before a push is stored, gitleaks, the open-source secret scanner, checks it for keys pasted into code. A push holding one is refused, as described under secret scanning.
Example
A hardware wholesaler's order app needs a key for its freight carrier's API. The agent declares the name and sends the office manager a link, and she pastes the key into the dashboard. When the carrier issues a new key, she replaces it and the app restarts with the new value.
For your coding agent
secrets: [CARRIER_API_KEY]
whisk secrets set CARRIER_API_KEY prints a link where a person pastes the value; the command never takes the value itself. The whisk.yaml reference covers the secrets list.