When you call the Secrets API or a Browserbase SDK directly, encrypt values locally before creating or updating a secret. Fetch the project keypair, seal the value with its public key, and send the resulting
sealedSecretValue and keypairId. The Browse CLI performs these steps for you.Use a secret in a Function
Attach a secret to a Function, then read it from
context.secrets.Create a secret
1
Install the Browse CLI
Install or update the CLI:
2
Set your Browserbase API key
Export your API key in the terminal that runs the Browse CLI:Browserbase resolves the project from this API key. You don’t need a Project ID.
3
Create the secret
Choose the name that your workload will use, then run:When
Secret value: appears, paste the secret value and press Enter. The terminal does not display the value while you enter it.4
Check the secret metadata
- Browse CLI
- Node.js
- Python
List your secrets:Get one secret by ID:
Update a secret
Replace the stored value without changing the secret ID or its Function attachments:Delete a secret
Delete a secret by ID:- Browse CLI
- Node.js
- Python
How Browserbase handles secret values
- The Browse CLI encrypts each value before upload.
- Browserbase stores the encrypted value.
- Get and list operations return metadata only.
- Browserbase exposes a value only to a Function that has the secret attached.
Next step
Add secrets to a Function
Attach the secret, read it in Function code, and test a deployed invocation.