None
🔑 Secrets
Keep passwords and API keys in the vault, and hand them to scripts without showing them to the agent.
What you can do
- Store secrets by name, grouped in profiles such as
smtporstripe - Read one value, or list the names
- Load a
.envfile into a profile - Run a command with a profile's secrets as environment variables
Setup
agentio secrets profile add --profile smtp
agentio secrets set SMTP_PASSWORD --profile smtp
agentio asks for the value without showing it.
Good to know
- Names must be valid environment variable names: letters, digits and
_, not starting with a digit. listshows only names. Add--revealto see values.execkeeps values out of the agent's context, but the command it runs can still print them.
Command reference
-
agentio secrets set <key> [value]Add or replace one secret
--profile <name> -
agentio secrets get <key>Print one secret's value, with no added newline
--profile <name> -
agentio secrets listList secret names; --reveal adds the values
--reveal--profile <name>--json -
agentio secrets unset <key>Remove one secret
--profile <name> -
agentio secrets import <file>Load secrets from a dotenv file; existing names are replaced
--profile <name> -
agentio secrets exec [command...]Run a command with the profile's secrets as environment variables
--profile <name>
Related changelog entries
- feat run a command with a profile's secrets in its environment eec71d0
- feat import secrets from a dotenv file 79ded54
- feat add secrets plugin with set, get, list and unset dc99d13
- feat parse dotenv files for import 4e6c154
- feat validate secret names and read the stored map bd3d932
- fix let Ctrl-D and Ctrl-C cancel the hidden prompt bf60a94
- fix treat a spaced # after = as a comment and keep names out of errors cdb4108