Skip to content
Trigora
Start building →

Secrets

Project secrets are credentials for effect code on Trigora Cloud. They are encrypted at rest. The API and dashboard return the name and timestamps. They do not return the value.

Set a secret with the CLI. The command always uses TRIGORA_TOKEN and the project named in trigora.toml.

Terminal window
trigora secrets set OPENAI_API_KEY

The value is read from a hidden prompt, or from stdin when piped. It is not a command argument. List and delete print names only.

Terminal window
trigora secrets list
trigora secrets delete OPENAI_API_KEY

Names look like environment variables, such as OPENAI_API_KEY. Names that start with TRIGORA_ are reserved.

Effect code reads the current value from the runtime environment:

await effect("call-openai", async () => {
const key = process.env.OPENAI_API_KEY;
});

Python effect code reads os.environ. Rust effect code reads std::env::var. There is no secret SDK.

A replace or delete applies on the next effect attempt. An attempt that has already started keeps the environment it started with. Waiting until tomorrow and then resuming uses the values stored at that attempt. Program artifacts stay immutable. Credentials are not pinned to a Program version.

A Program deployed before secrets support must be redeployed once before its effects can receive managed secrets. After that deploy, changing a value does not require another deploy.

Workspace owners and admins can create, replace, and delete secrets in the dashboard. Members can list names. A workspace API token can also change secrets, because the CLI authenticates with TRIGORA_TOKEN.

trigora dev does not read Cloud secrets. Local effect execution uses the process environment, including a project .env file.

Do not put credentials in event payloads or Program constants. Those values may be stored with the Execution. See Production considerations.