Manage secrets
Create, inspect, rotate, and revoke workspace secrets.
Manage secrets from the dashboard or the tenki secrets CLI. Commands use the workspace selected during login.
Access permissions
Your account needs workspace-edit permission. When creating an API key or approving a CLI login, select Allow Secrets access. If an existing key lacks access, create a replacement or log in again and select that option.
Create a secret
Use an authenticated CLI from the quickstart.
This example saves a GitHub personal access token. Use a token with only the permissions your application needs.
tenki secrets create GITHUB_TOKENWait for Secret value (hidden):, paste your token, and press Enter. Paste only the token, without a Bearer prefix. The prompt hides your input and keeps the value out of your shell command history.
Keep the secret ID printed by the command. The name is used in requests; the ID is used to manage the secret later.
For a complete configuration file or private key, read the value from a local file instead:
tenki secrets create SERVICE_CONFIG --file ./service-config.jsonFile input preserves the exact bytes, including trailing newlines. You can also use --stdin or --from-env VARIABLE_NAME for scripts.
Inspect a secret
In the dashboard, open your workspace's Secrets page. Secret values and request policies are managed separately.
From the CLI, inspect metadata with:
tenki secrets list
tenki secrets get SECRET_ID
tenki secrets versions SECRET_IDReplace SECRET_ID with the ID returned when you created the secret. Listing and inspecting a secret do not reveal its value.
Rotate a value
A secret's version identifies a stored value. Its revision identifies the current state of its metadata and protects updates against concurrent changes.
Read the current revision with secrets get, then update the value. This example reads a replacement token from a local file:
tenki secrets update SECRET_ID --revision REVISION --file ./replacement-token.txtReplace REVISION with the number you just read. File input preserves the exact bytes, including a trailing newline, so ensure the file contains only the token. You can also use --stdin or --from-env VARIABLE_NAME for automation.
The new value becomes active. Subsequent injected requests use it immediately; guest environment variables and files need a new sandbox. Tenki does not refresh or renew credentials with the provider for you.
To select an earlier, unrevoked version:
tenki secrets update SECRET_ID --revision REVISION --active-version VERSIONRevoke or delete a secret
Use the current revision for either operation:
tenki secrets revoke SECRET_ID --revision REVISIONThis revokes all current value versions and prevents further resolution of the secret. Revoked versions cannot be used again, but you can restore the secret by updating it with a new value. To revoke only one version, add --version VERSION.
To delete a secret you no longer need:
tenki secrets delete SECRET_ID --revision REVISIONDeleting or revoking a Tenki secret does not revoke the credential at its provider. Recreating a secret or policy with the same name does not silently reconnect existing policy or sandbox attachments to the new object.
Use a saved secret
Follow Using secrets in a sandbox for environment variables, files, and transparent injection. The guide also explains what happens during rotation, revocation, and pause/resume.