Secrets

API keys and tokens, encrypted and out of sight

Store the API keys, tokens and credentials your backend needs as project secrets. They're encrypted at rest, never shown again after you save them, and decrypted only at the moment a workflow step uses them.

The same task, three ways

Every task works three ways, and all of them change the same project. Here's one: store a Stripe key and use it from a workflow.

The Anythink dashboard

Save the key once, then reference it by name in a workflow step.

The Anythink CLI

The value is prompted for, so it never lands in your shell history.

$ anythink secrets create STRIPE_SECRET_KEY$ anythink secrets list
  • ✓STRIPE_SECRET_KEY stored, encrypted with AES-256-GCM
  • ✓list shows names and dates, never values

Claude, through MCP

Keep the value out of chat: store it in the dashboard or CLI, then ask the assistant to use it.

you › “Add a step to the Sync Stripe customers workflow that calls the Stripe customers API, using the STRIPE_SECRET_KEY secret as a bearer token.”

  • ✓Added a Call An API step
  • ✓Authorization header references {{ $anythink.secrets.STRIPE_SECRET_KEY }}
  • ✓The secret's value was never read or shown

Secrets your workflows can use, and nobody can read

One encrypted store for every credential your backend touches: AI provider keys, payment keys, webhook tokens and third-party API keys.

Encrypted at rest with AES-256-GCM

Every value is encrypted before it's stored, using AES-256-GCM with a key derived through PBKDF2 (600,000 iterations). The plaintext never sits in your database.

In practice

Store a key once, then use it from a workflow

store the secret.sh
anythink secrets create STRIPE_SECRET_KEY
# prompts for the value, so it never lands in your shell history

What teams keep in secrets

01

AI provider keys

Keep a Claude, OpenAI or Grok key in one place and reference it from every workflow that summarises, translates or analyses. To rotate it, update the secret, not each workflow.

02

Payment and webhook credentials

Stripe keys, webhook signing secrets and partner API tokens live in one place instead of being pasted into each workflow. Send them in a header or the body: Call an API logs header names, never their values.

03

Per-environment configuration

Staging and production projects each hold their own secrets under the same names, so a workflow promoted with anythink migrate picks up the right credentials in each.

Frequently Asked Questions

Still have questions?

Get in Touch

Ready to go?

Create an account and start building