Secrets
Site secrets hold values your functions and cron jobs need at runtime — API keys, tokens, webhook signing keys — without ever writing them into source, config, or logs.
Setting a secret
Set secrets through the CLI, and always pass the value via stdin so it never lands in your shell history or process list:
printf '%s' "$OPENAI_API_KEY" | interfold secrets set OPENAI_API_KEY --site <site-id>
List the secrets on a site (names and metadata only — never values):
interfold secrets list --site <site-id>
Remove one:
interfold secrets rm OPENAI_API_KEY --site <site-id>
Secret names may contain letters, numbers, and underscores. Empty values are valid.
Reading a secret in a handler
Functions and cron jobs access secrets at runtime through ctx.secrets:
export async function handler(req: Request, ctx: InterfoldContext) {
const apiKey = await ctx.secrets.get('OPENAI_API_KEY')
if (!apiKey) {
return new Response('Not configured', { status: 503 })
}
// Use apiKey to call an upstream service…
return Response.json({ configured: true })
}
Never return a secret value in a response or log it. Treat ctx.secrets.get(...)
output as sensitive.
Verifying without revealing
Prefer secrets list to confirm a secret exists. Only use secrets get when you
explicitly need to reveal the value:
interfold secrets list --site <site-id> # check existence
interfold secrets get OPENAI_API_KEY --site <site-id> --raw # reveal (rare)
Good practice
- Store third-party credentials as secrets, not in function source.
- Rotate by re-running
secrets setwith the new value — it replaces in place. - Keep secret names descriptive and stable; functions reference them by name.