Secrets Manager

Secrets Manager stores credentials such as API keys, tokens, and connection strings, and lets your managed deployments read them at runtime without hardcoding them. This page is for developers who deploy workflows on AI Studio and need to pass credentials to them.

Secrets are scoped to a workspace and shared by its members, and access follows your workspace role. Setting a new value creates a new version of the secret.

i
Information

Secrets Manager is in Public Preview. Behavior and limits can change.

Before you begin

Before you begin

  • Any workspace member can see the list of secrets and their names.
  • Creating, editing, deleting, and restoring secrets requires the Developer Workspace role, which is included in the Workspace Contributor and Workspace Admin roles. See Roles and permissions.

Limits:

  • Names: up to 256 characters.
  • Values: up to 64 KiB.
  • Descriptions: up to 512 bytes.
Create a secret

Create a secret

  1. Open Studio›Secrets Manager ↗.
  2. Select Create secrets.
  3. Enter a Name. Names can contain letters, digits, -, and _, are normalized to lowercase (MySecret is stored as mysecret), and are unique within the workspace.
  4. Enter the Value.
  5. Optionally add a Description.
  6. Select Create Secret.

The value is stored as the first version of the secret. It isn't shown again after you create it.

Manage secrets

Manage secrets

From the list, you can search by name and open a secret's actions menu to:

  • Edit the description, or set a new value. Setting a new value creates a new version; earlier versions are retained.
  • Delete the secret. Delete is a soft delete: the secret stops resolving but remains recoverable, with no expiry.

A deployment that is already running keeps the value it started with. Its next start fails to resolve a deleted secret until you restore it.

To recover a deleted secret:

  1. Open More actions.
  2. Select View deleted secrets.
  3. Select Restore on the secret you want to recover.
Secret values are write-only

Secret values are write-only

Secret values are write-only: after you create a secret or set a new value, the console masks the value and you can't read it back through the console. Only authorized workloads read values, through the API, and each read is audited.

Warning

If you need a value elsewhere, keep your own copy. To change a value, set a new one, which creates a new version. Don't commit secret values to version control.

Reference secrets from deployments

Reference secrets from deployments

Managed deployments read secrets at runtime by reference, so you don't have to embed a value in your code or configuration. Bind a secret to a deployment, and the deployment configuration stores the reference. The platform resolves the value when the workload starts, using the identity of the workload, scoped to the workspace of the workload.

A reference has the form secret:workspace:<name>. It always resolves to the latest version of the secret.

To bind secrets, see Secrets on managed deployments. Bound secrets are also passed to the Docker build as build args, which that page covers along with its caveats.

Rotate a secret

Rotate a secret

To rotate a secret, set a new value, then restart the deployments that use it. A running workload keeps the value it started with until it restarts and resolves the reference again.