Secrets are encrypted values — API keys, tokens, and passwords — stored securely against your project. They are available to workflows at runtime but their values are never exposed in the dashboard, logs, or API responses.
Any time a workflow needs to call an external API, it needs credentials — an API key, a bearer token, a webhook secret. Rather than pasting these values directly into your workflow configuration (where they would appear in logs and step outputs), you store them as secrets and reference them by name.
Secrets are encrypted at rest. Only the workflow engine can decrypt them at runtime, and only for the project they belong to.
Go to Settings → Secrets in your Anythink dashboard. From here you can:
# List all secret keys
anythink secrets list
# Create a new secret (you will be prompted to enter the value securely)
anythink secrets create STRIPE_SECRET_KEY
anythink secrets create ANTHROPIC_API_KEY
# Rotate a secret (overwrites the existing value)
anythink secrets update STRIPE_SECRET_KEY
# Delete a secret
anythink secrets delete STRIPE_SECRET_KEY --yes
Values are entered via a hidden prompt — they are never visible in your terminal history or shell output.
Reference a secret in any workflow step that supports template syntax using:
{{$anythink.secrets.YOUR_KEY_NAME}}
The most common use is in the Call an API step headers or body. For example, to call an external API that requires an API key:
Headers:
{
"Authorization": "Bearer {{$anythink.secrets.MY_SERVICE_TOKEN}}",
"x-api-key": "{{$anythink.secrets.MY_API_KEY}}"
}
Body:
{
"api_key": "{{$anythink.secrets.STRIPE_SECRET_KEY}}",
"amount": "{{ $anythink.trigger.data.amount }}"
}
At runtime, the workflow engine decrypts the secret value and substitutes it into the payload before the request is made. The decrypted value never appears in job history or step logs.
STRIPE_SECRET_KEY not KEY1)secrets update to rotate keys when you cycle credentials in external services