> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browserbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets

> Store encrypted credentials and make them available only to the Browserbase Functions that need them.

Browserbase Secrets stores credentials that your Functions need at runtime. Create a secret once, attach it to a Function, and read the value from `context.secrets` when an invocation starts.

Use Secrets for values such as third-party API tokens, service credentials, and other sensitive configuration that should not live in Function code.

## How secrets work

1. The Browse CLI gets your project's public key and encrypts the value on your machine.
2. Browserbase stores the encrypted value and returns a secret ID.
3. You attach the secret ID to a Function.
4. Browserbase loads the attached value into `context.secrets` when an invocation starts.

A Function can read only the secrets attached to it. Function secrets are not environment variables and are not available through `process.env` in a deployed invocation.

## Access model

| Action | Behavior |
| - | - |
| Create | Stores an encrypted value under a name such as `SERVICE_TOKEN`. |
| Get or list | Returns the secret ID and name, never the stored value. |
| Attach | Grants one Function access on its next invocation. |
| Update | Replaces the value while keeping the secret ID and Function attachments. |
| Detach | Removes one Function's access without deleting the secret. |
| Delete | Deletes the secret and removes all of its Function attachments. |

Secrets and Functions must belong to the same Browserbase project. Browserbase resolves the project from the API key used for each command or SDK request.

## Secrets and invocation parameters

Use a secret for a sensitive value that a Function needs across invocations. Use [invocation parameters](/platform/functions/invoke#pass-parameters) for non-sensitive input that changes from one invocation to the next.

For local development, use a local environment variable as a fallback. Function attachments apply only to deployed invocations.

## Next steps

<CardGroup cols={2}>
  <Card title="Get started with secrets" icon="key" href="/platform/secrets/getting-started">
    Create, inspect, update, and delete a secret.
  </Card>

  <Card title="Use secrets in Functions" icon="bolt" href="/platform/functions/secrets">
    Attach a secret and read it from Function code.
  </Card>
</CardGroup>
