# Overview (https://tenki.cloud/docs/secrets)

> For the complete documentation index, see [llms.txt](https://tenki.cloud/llms.txt)

Store credentials in your workspace and choose how your applications use them.

A secret is a named value in your Tenki workspace, such as an API key, an access token, or a configuration file. Tenki encrypts the value at rest. You can inspect its name and other metadata, but the management API does not return the stored value.

For example, save a GitHub token as `GITHUB_TOKEN`. Your application refers to that name, so you do not have to put the token in source code or a container image.

## Choose how to use a secret

| Your application needs                           | Use                                                                                   | Where the real value goes                       |
| ------------------------------------------------ | ------------------------------------------------------------------------------------- | ----------------------------------------------- |
| To call an HTTPS API without receiving the token | [Transparent injection](https://tenki.cloud/docs/sandbox/secrets.md#call-an-api-with-transparent-injection) | Into the outgoing request, outside the sandbox. |
| A token in an environment variable               | [Load a `.env` file](https://tenki.cloud/docs/sandbox/secrets.md#deliver-a-secret-file)                     | Into your app's process inside the sandbox.     |
| A credential or configuration file               | [Secret files](https://tenki.cloud/docs/sandbox/secrets.md#deliver-a-secret-file)                           | Into a file inside the sandbox.                 |

All three use the same workspace secrets. Saving a secret does not automatically give it to a sandbox.

Transparent injection uses a [request policy](https://tenki.cloud/docs/secrets/request-policies.md) to say which requests may use a secret. Environment variables and files do not need request policies: they give the application the real value.

## Get started

1. [Save a secret](https://tenki.cloud/docs/secrets/manage-secrets.md#create-a-secret) in your workspace.
2. For transparent injection, [create a request policy](https://tenki.cloud/docs/secrets/request-policies.md#create-a-policy).
3. [Use it in a sandbox](https://tenki.cloud/docs/sandbox/secrets.md) with the CLI or an SDK.

To replace a token later, [rotate its value](https://tenki.cloud/docs/secrets/manage-secrets.md#rotate-a-value). Injected requests pick up the active value; values already delivered into a sandbox stay there until you create a new sandbox.