What to Store as Secrets
Use environment secrets for any value that’s sensitive or that changes between environments:- API keys — Stripe secret keys, webhook signing secrets, third-party service keys
- Tokens — access tokens for external APIs
- Configuration — values you don’t want committed into your codebase
Where to Set Them
Environment variables and secrets are managed per app in the app’s settings. Each app you build has its own set — they aren’t shared between apps.1
Open your project's settings
Go to the settings for the app you’re building.
2
Open Environment
Select Environment to see the app’s environment variables and secrets.
3
Add a key and value
Enter the name (for example,
STRIPE_SECRET_KEY) and paste its value, marking it as a secret if it’s sensitive. Use the exact name your app’s code reads.4
Save
Save your changes. Your secret is stored securely and applied to your app the next time you publish.
Secrets you set apply to your published app — the preview doesn’t read them. If you add or change a secret after publishing, it takes effect the next time you publish. See Deploying Your App.
Finding the Secrets Your App Needs
Fabricate’s agent can’t set secrets for you or see their values. When you ask for an integration that needs credentials — payments, an external API, or anything similar — the code it writes reads each value by name, and your job is to supply the values in app settings. For example, Stripe payment code typically reads keys such asSTRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET. Check the exact names in the Code view, then set each one in Environment.
How Your App Uses Them
Fabricate-generated apps run their backend on Cloudflare Workers. Secrets you set are exposed to your published app’s server code at runtime, so its API routes can read them without the values ever appearing in your source code. The preview runs without them, so a feature that needs a secret only works in your published app.Security Best Practices
- Never hard-code secrets. Keep keys out of components, API routes, and anything that could end up in version control.
- Use test keys while building. For services like Stripe, use test-mode keys during development and switch to live keys only when you go to production.
- Keep secrets per app. Don’t reuse one app’s production keys in another app.
- Rotate if exposed. If a secret is ever leaked or pasted somewhere public, revoke it at the provider and set a fresh value.
- Mind GitHub. If you push your code to GitHub, secrets stay in app settings — they are not committed — so your repository never contains them.
Frequently Asked Questions
Are my secrets visible in my code or exports?
Are my secrets visible in my code or exports?
No. Secrets live in app settings, not in your source files. Downloading your code or pushing it to GitHub does not include them.
Do secrets carry over when I redeploy?
Do secrets carry over when I redeploy?
Yes. Secrets set in app settings persist across redeploys. If you change a secret, the live app uses the new value from your next publish.
Can I use different values for testing and production?
Can I use different values for testing and production?
Each app has one set of secrets, and they apply to your published app. A common pattern is to publish with a service’s test keys first, then switch to live keys and republish when you’re ready for real use.
How do I know which secrets an integration needs?
How do I know which secrets an integration needs?
Check the code in the Code view for the names it reads, then add each one in your app’s settings under Environment.
What happens if a required secret is missing?
What happens if a required secret is missing?
The feature that depends on it will fail — and it always fails in the preview, which never has secrets. Add the missing secret, confirm the name matches exactly, and publish again.
Related
Payments
What to know before adding Stripe — and the keys it needs.
Deploying Your App
Publish your app and apply your secrets.