How it works
secrets.setandsecrets.getreturn an opaque secret reference (a$secret:...string), not the actual value.- When this reference is used inside a
fetchinstruction (in the URL, headers, body, query, or auth fields), the platform automatically resolves it to the real value just before the HTTP call. - The resolved value is redacted from all logs and events.
secrets.get right before using the reference — do not store it for later reuse.
Scopes
Functions
set — Store or update a secret
Returns a
$secret:... reference string. If a secret with the same name and scope already exists, it is updated.
get — Retrieve a secret reference
Returns a
$secret:... reference string, or { error: "not_found" } if the secret does not exist (or has expired).
delete — Remove a secret
Returns
{ deleted: true } on success, or { error: "not_found" }.
Using secret references in fetch
Pass the reference returned byset or get wherever a sensitive value is needed in a fetch instruction. The platform resolves it transparently:
fetch fields: url, headers, body, query, and auth (including auth.awsv4).
Complete example — storing and using an OAuth token
Error handling
All three functions return an error object instead of throwing when the error is actionable:
Use
onError or a conditions block to handle these: