powered by

Secrets

Secrets are encrypted values — API keys, tokens, and passwords — stored securely against your project. They are available to workflows at runtime but their values are never exposed in the dashboard, logs, or API responses.

What secrets are for

Any time a workflow needs to call an external API, it needs credentials — an API key, a bearer token, a webhook secret. Rather than pasting these values directly into your workflow configuration (where they would appear in logs and step outputs), you store them as secrets and reference them by name.

Secrets are encrypted at rest. Only the workflow engine can decrypt them at runtime, and only for the project they belong to.


Managing secrets

In the dashboard

Go to Settings → Secrets in your Anythink dashboard. From here you can:

  • See all your stored secret keys (names only — values are never shown)
  • Add a new secret
  • Rotate (overwrite) an existing secret
  • Delete a secret

Via the CLI

bash
# List all secret keys
anythink secrets list

# Create a new secret (you will be prompted to enter the value securely)
anythink secrets create STRIPE_SECRET_KEY
anythink secrets create ANTHROPIC_API_KEY

# Rotate a secret (overwrites the existing value)
anythink secrets update STRIPE_SECRET_KEY

# Delete a secret
anythink secrets delete STRIPE_SECRET_KEY --yes

Values are entered via a hidden prompt — they are never visible in your terminal history or shell output.


Using secrets in workflows

Reference a secret in any workflow step that supports template syntax using:

text
{{$anythink.secrets.YOUR_KEY_NAME}}

The most common use is in the Call an API step headers or body. For example, to call an external API that requires an API key:

Headers:

json
{
  "Authorization": "Bearer {{$anythink.secrets.MY_SERVICE_TOKEN}}",
  "x-api-key": "{{$anythink.secrets.MY_API_KEY}}"
}

Body:

json
{
  "api_key": "{{$anythink.secrets.STRIPE_SECRET_KEY}}",
  "amount": "{{ $anythink.trigger.data.amount }}"
}

At runtime, the workflow engine decrypts the secret value and substitutes it into the payload before the request is made. The decrypted value never appears in job history or step logs.


Best practices

  • One secret per credential — give each key a clear, descriptive name (STRIPE_SECRET_KEY not KEY1)
  • Rotate regularly — use secrets update to rotate keys when you cycle credentials in external services
  • Delete unused secrets — if a workflow no longer uses a secret, remove it to keep things tidy
  • Never hardcode sensitive values — if you find a token or password pasted directly into a workflow step body, move it to secrets