Build features

Secrets

Keep API keys out of your code. Your app reads them from env.

AI tools often write API keys straight into the code. Anyone who can see the code can then copy the key. On Inhaus, keys go in secrets instead: stored encrypted, never shown again, and given to your app's server code as env.NAME.

Set a secret from your AI tool

Store my HubSpot token as a secret for the lead tracker: pat-na1-...

Your AI tool calls set_secret. The secret works from the next request. No redeploy needed.

Set a secret in the dashboard

Open the app, go to Secrets, and choose Add secret. Replace changes a value. You can see each secret's name, who set it, from where and when, but never its value.

Read it in your code

worker.ts
export default {
  async fetch(request: Request, env: Env) {
    const res = await fetch('https://api.hubapi.com/crm/v3/objects/contacts', {
      headers: { authorization: `Bearer ${env.HUBSPOT_TOKEN}` },
    });
    return Response.json(await res.json());
  },
};

Naming rules

  • Capital letters, digits and underscores, starting with a letter: HUBSPOT_TOKEN, OPENAI_API_KEY, SHEET_ID_2.
  • 2 to 64 characters.
  • Names starting with INHAUS_ are reserved.
  • Values can be up to 5 KB.

Remove a secret

Choose the × next to it in the Secrets tab. Code that still reads it gets undefined.

Keys found in code

If the security scan finds a key written into the code, it is a blocking issue. The fix is one click: Move to secrets stores the value as a secret, rewrites the line to read env.NAME, and deploys a new version. See Fixing issues.

How secrets are stored

Values are encrypted and kept in a secrets vault, separate from the rest of your app's data. They are never written to logs, never returned by any tool or API, and never sent to the AI review.