Skip to main content
Secrets store credentials that your Browserbase workloads need at runtime. Use the Browse CLI to create and update encrypted values. Use the CLI or a Browserbase SDK to inspect and delete them.
When you call the Secrets API or a Browserbase SDK directly, encrypt values locally before creating or updating a secret. Fetch the project keypair, seal the value with its public key, and send the resulting sealedSecretValue and keypairId. The Browse CLI performs these steps for you.

Use a secret in a Function

Attach a secret to a Function, then read it from context.secrets.

Create a secret

1

Install the Browse CLI

Install or update the CLI:
2

Set your Browserbase API key

Export your API key in the terminal that runs the Browse CLI:
Browserbase resolves the project from this API key. You don’t need a Project ID.
3

Create the secret

Choose the name that your workload will use, then run:
When Secret value: appears, paste the secret value and press Enter. The terminal does not display the value while you enter it.
The Browse CLI encrypts the value on your machine. Save the secret ID from the response. You need it for later commands.
4

Check the secret metadata

List your secrets:
Get one secret by ID:
These operations return the secret ID and name. They don’t return the secret value.

Update a secret

Replace the stored value without changing the secret ID or its Function attachments:
The command prompts for the new value and encrypts it with the current project public key.

Delete a secret

Delete a secret by ID:
Deleting a secret also removes its Function attachments. A deleted secret is not available to later Function invocations.

How Browserbase handles secret values

  • The Browse CLI encrypts each value before upload.
  • Browserbase stores the encrypted value.
  • Get and list operations return metadata only.
  • Browserbase exposes a value only to a Function that has the secret attached.

Next step

Add secrets to a Function

Attach the secret, read it in Function code, and test a deployed invocation.