> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browserbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get started with secrets

> Create, inspect, update, and delete encrypted secrets with the Browse CLI.

Secrets store credentials that your Browserbase workloads need at runtime. Use the Browse CLI to create and update encrypted values. Use the CLI or a Browserbase SDK to inspect and delete them.

<Note>
  When you call the Secrets API or a Browserbase SDK directly, encrypt values locally before creating or updating a secret. Fetch the project keypair, seal the value with its public key, and send the resulting `sealedSecretValue` and `keypairId`. The Browse CLI performs these steps for you.
</Note>

<Card title="Use a secret in a Function" icon="bolt" href="/platform/functions/secrets">
  Attach a secret to a Function, then read it from `context.secrets`.
</Card>

## Create a secret

<Steps>
  <Step title="Install the Browse CLI">
    Install or update the CLI:

    ```bash theme={null}
    npm install --global browse@latest
    ```
  </Step>

  <Step title="Set your Browserbase API key">
    Export your API key in the terminal that runs the Browse CLI:

    ```bash theme={null}
    export BROWSERBASE_API_KEY="your_api_key"
    ```

    Browserbase resolves the project from this API key. You don't need a Project ID.
  </Step>

  <Step title="Create the secret">
    Choose the name that your workload will use, then run:

    ```bash theme={null}
    browse cloud secrets create SERVICE_TOKEN
    ```

    When `Secret value:` appears, paste the secret value and press Enter. The terminal does not display the value while you enter it.

    <Tip>
      The Browse CLI encrypts the value on your machine. Save the secret ID from the response. You need it for later commands.
    </Tip>
  </Step>

  <Step title="Check the secret metadata">
    <Tabs>
      <Tab title="Browse CLI">
        List your secrets:

        ```bash theme={null}
        browse cloud secrets list
        ```

        Get one secret by ID:

        ```bash theme={null}
        browse cloud secrets get <secret-id>
        ```
      </Tab>

      <Tab title="Node.js">
        ```typescript Node.js theme={null}
        import { Browserbase } from "@browserbasehq/sdk";

        const bb = new Browserbase({
          apiKey: process.env.BROWSERBASE_API_KEY!,
        });

        const secrets = await bb.secrets.list();
        console.log(secrets.data);

        const secret = await bb.secrets.retrieve("<secret-id>");
        console.log(secret);
        ```
      </Tab>

      <Tab title="Python">
        ```python Python theme={null}
        import os
        from browserbase import Browserbase

        bb = Browserbase(api_key=os.environ["BROWSERBASE_API_KEY"])

        secrets = bb.secrets.list()
        print(secrets.data)

        secret = bb.secrets.retrieve("<secret-id>")
        print(secret)
        ```
      </Tab>
    </Tabs>

    These operations return the secret ID and name. They don't return the secret value.
  </Step>
</Steps>

## Update a secret

Replace the stored value without changing the secret ID or its Function attachments:

```bash theme={null}
browse cloud secrets update <secret-id>
```

The command prompts for the new value and encrypts it with the current project public key.

## Delete a secret

Delete a secret by ID:

<Tabs>
  <Tab title="Browse CLI">
    ```bash theme={null}
    browse cloud secrets delete <secret-id>
    ```
  </Tab>

  <Tab title="Node.js">
    ```typescript Node.js theme={null}
    import { Browserbase } from "@browserbasehq/sdk";

    const bb = new Browserbase({
      apiKey: process.env.BROWSERBASE_API_KEY!,
    });

    await bb.secrets.delete("<secret-id>");
    ```
  </Tab>

  <Tab title="Python">
    ```python Python theme={null}
    import os
    from browserbase import Browserbase

    bb = Browserbase(api_key=os.environ["BROWSERBASE_API_KEY"])

    bb.secrets.delete("<secret-id>")
    ```
  </Tab>
</Tabs>

Deleting a secret also removes its Function attachments. A deleted secret is not available to later Function invocations.

## How Browserbase handles secret values

* The Browse CLI encrypts each value before upload.
* Browserbase stores the encrypted value.
* Get and list operations return metadata only.
* Browserbase exposes a value only to a Function that has the secret attached.

## Next step

<Card title="Add secrets to a Function" icon="key" href="/platform/functions/secrets">
  Attach the secret, read it in Function code, and test a deployed invocation.
</Card>
