Overview
Store credentials in your workspace and choose how your applications use them.
A secret is a named value in your Tenki workspace, such as an API key, an access token, or a configuration file. Tenki encrypts the value at rest. You can inspect its name and other metadata, but the management API does not return the stored value.
For example, save a GitHub token as GITHUB_TOKEN. Your application refers to that name, so you do not have to put the token in source code or a container image.
Choose how to use a secret
| Your application needs | Use | Where the real value goes |
|---|---|---|
| To call an HTTPS API without receiving the token | Transparent injection | Into the outgoing request, outside the sandbox. |
| A token in an environment variable | Load a .env file | Into your app's process inside the sandbox. |
| A credential or configuration file | Secret files | Into a file inside the sandbox. |
All three use the same workspace secrets. Saving a secret does not automatically give it to a sandbox.
Transparent injection uses a request policy to say which requests may use a secret. Environment variables and files do not need request policies: they give the application the real value.
Get started
- Save a secret in your workspace.
- For transparent injection, create a request policy.
- Use it in a sandbox with the CLI or an SDK.
To replace a token later, rotate its value. Injected requests pick up the active value; values already delivered into a sandbox stay there until you create a new sandbox.