Secrets
Keep API keys and passwords your app needs out of its code, in the app's .env file.
Keep API keys and passwords your app needs out of its code, in the app's .env file.
Tools → Secrets holds the API keys, passwords and tokens your app uses, like STRIPE_SECRET_KEY or OPENAI_API_KEY. Secrets are the variables in the app’s .env file inside its sandbox, and the app reads them as environment variables. Laravel, Vite, Next.js and Node’s dotenv all read this file.
The panel lists every secret by name, with its value hidden. Type in Filter secrets by name to narrow the list.
To add several secrets at once, copy lines like NAME=value, for example from an .env file or another host’s environment settings, and paste them into a Name field. Each line becomes its own row, ready to check before you save.
STRIPE_SECRET_KEY=sk_live_51H8x
export RESEND_API_KEY="re_123" # email
Comments, blank lines and export are skipped, and quotes are removed. Multi-line values in double quotes stay whole. If a name already exists, its row says that saving replaces the current value. Only the names marked that way are overwritten, and everything is saved at once with a single restart.
Values can be any text, including spaces, quotes and multi-line keys such as PEM certificates. The app restarts after each change so it picks up the new values.
The agent reads secrets from the environment by name. It doesn’t put their values in code, commits or the chat. When the app needs a key that isn’t there yet, the agent asks you to add it in Tools → Secrets by its exact name. Add it there rather than pasting it in the chat.
OneDrop doesn’t store secrets. They stay in the app’s .env in its sandbox,
and the panel only fetches a value when you reveal or copy it. Anyone who
can open the project can see them. .env is added to the app’s
.gitignore so it stays out of the app’s git history.
Sign-in provider keys saved in Users & Auth are secrets too, so they appear here as well.