# Manage secrets (https://tenki.cloud/docs/secrets/manage-secrets)

> For the complete documentation index, see [llms.txt](https://tenki.cloud/llms.txt)

Create, inspect, rotate, and revoke workspace secrets.

Manage secrets from the dashboard or the `tenki secrets` CLI. Commands use the workspace selected during login.

## Access permissions

Your account needs workspace-edit permission. When creating an API key or approving a CLI login, select **Allow Secrets access**. If an existing key lacks access, create a replacement or log in again and select that option.

## Create a secret

Use an authenticated CLI from the [quickstart](https://tenki.cloud/docs/sandbox/quickstart.md).

This example saves a GitHub personal access token. Use a token with only the permissions your application needs.

```bash
tenki secrets create GITHUB_TOKEN
```

Wait for `Secret value (hidden):`, paste your token, and press Enter. Paste only the token, without a `Bearer ` prefix. The prompt hides your input and keeps the value out of your shell command history.

Keep the secret ID printed by the command. The name is used in requests; the ID is used to manage the secret later.

For a complete configuration file or private key, read the value from a local file instead:

```bash
tenki secrets create SERVICE_CONFIG --file ./service-config.json
```

File input preserves the exact bytes, including trailing newlines. You can also use `--stdin` or `--from-env VARIABLE_NAME` for scripts.

## Inspect a secret

In the dashboard, open your workspace's **Secrets** page. Secret values and [request policies](https://tenki.cloud/docs/secrets/request-policies.md) are managed separately.

From the CLI, inspect metadata with:

```bash
tenki secrets list
tenki secrets get SECRET_ID
tenki secrets versions SECRET_ID
```

Replace `SECRET_ID` with the ID returned when you created the secret. Listing and inspecting a secret do not reveal its value.

## Rotate a value

A secret's **version** identifies a stored value. Its **revision** identifies the current state of its metadata and protects updates against concurrent changes.

Read the current revision with `secrets get`, then update the value. This example reads a replacement token from a local file:

```bash
tenki secrets update SECRET_ID --revision REVISION --file ./replacement-token.txt
```

Replace `REVISION` with the number you just read. File input preserves the exact bytes, including a trailing newline, so ensure the file contains only the token. You can also use `--stdin` or `--from-env VARIABLE_NAME` for automation.

The new value becomes active. Subsequent injected requests use it immediately; guest environment variables and files need a new sandbox. Tenki does not refresh or renew credentials with the provider for you.

To select an earlier, unrevoked version:

```bash
tenki secrets update SECRET_ID --revision REVISION --active-version VERSION
```

## Revoke or delete a secret

Use the current revision for either operation:

```bash
tenki secrets revoke SECRET_ID --revision REVISION
```

This revokes all current value versions and prevents further resolution of the secret. Revoked versions cannot be used again, but you can restore the secret by updating it with a new value. To revoke only one version, add `--version VERSION`.

To delete a secret you no longer need:

```bash
tenki secrets delete SECRET_ID --revision REVISION
```

Deleting or revoking a Tenki secret does not revoke the credential at its provider. Recreating a secret or policy with the same name does not silently reconnect existing policy or sandbox attachments to the new object.

## Use a saved secret

Follow [Using secrets in a sandbox](https://tenki.cloud/docs/sandbox/secrets.md) for environment variables, files, and transparent injection. The guide also explains what happens during rotation, revocation, and pause/resume.