> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replit.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets

> Store credentials for external services as secrets and non-sensitive settings as configurations in your Replit project.

The Secrets tool stores and encrypts **secrets**, your Replit project's sensitive information.
These include API keys, authentication tokens, and database connection strings that your project uses to connect to external services.
For example, your project might need credentials to call a third-party API, connect to an authentication provider, or access a database.

When you add a secret, the tool automatically encrypts the data and makes it available to your Replit project as an environment variable.
This approach lets you eliminate hard-coding secrets in your code and reduce the risk of exposing them.

<Frame>
  <iframe width="100%" height="400" src="https://www.youtube.com/embed/qE_2Z8ReyWI" title="Secrets Project Editor tool" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen />
</Frame>

Hard-coding secrets in your codebase can lead to accidental exposure in the following scenarios:

* Sharing your code with others through a public Replit project or copy-paste
* Checking your code into version control in a public repository
* Live streaming or screen sharing your code

Use the Secrets tool to confidently share your code without worrying about exposing credentials.

<Frame caption="Secrets and Configurations in the Secrets tool. Project-specific secret names are redacted.">
  <img src="https://mintcdn.com/replit/fAZUw0LJRyEUb1kI/images/workspace/secrets-and-configurations.png?fit=max&auto=format&n=fAZUw0LJRyEUb1kI&q=85&s=ce568db53d05b59d82e3063c807a76bc" alt="Secrets tool showing masked secret values and a separate Configurations section for non-sensitive information" width="2488" height="1412" data-path="images/workspace/secrets-and-configurations.png" />
</Frame>

## Secrets versus configurations

The **Secrets** tool has separate sections for secrets and configurations. Both let your project's code read values as environment variables without hard-coding them.

| Type | Use for | Examples |
| - | - | - |
| **Secrets** | Sensitive information that must remain private | API keys, authentication tokens, and database connection strings |
| **Configurations** | Non-sensitive settings | Log levels, feature flags, and public service URLs |

Configurations are useful when a setting differs between testing on Replit and running your published project.
Use a secret whenever a value contains credentials or other sensitive data.

## Features

Secrets include the following features:

* **Encryption**: Protect your secrets using AES-256 encryption at rest and TLS encryption in transit
* **Project-level secrets**: Store and manage secrets that are specific to a Replit project
* **Configurations**: Manage non-sensitive environment variables alongside your secrets
* **Environment variable access**: Access your secrets from your code using environment variables
* **Collaborative access**: Share secrets with collaborators and team members

## Usage

<Note>
  Secrets are available for all deployment types except Static Deployments.
</Note>

### How to find Secrets

Open the **Secrets** tool from your project's tools pane:

1. Open your project in the Project Editor.
2. Select **Tools** at the top to open the tools pane.
3. Find the **Setup** section and select **Secrets**.

<Frame caption="Select Tools, then Secrets under Setup.">
  <img src="https://mintcdn.com/replit/fAZUw0LJRyEUb1kI/images/workspace/secrets-tool-navigation.png?fit=max&auto=format&n=fAZUw0LJRyEUb1kI&q=85&s=6571da9b2f604208dd8c7fb7f1032005" alt="Project Editor tools pane with the Tools button at the top and Secrets under the Setup heading" width="418" height="1094" style={{ width: "360px", maxWidth: "100%", height: "auto", objectFit: "contain" }} data-path="images/workspace/secrets-tool-navigation.png" />
</Frame>

The **Secrets** tool opens with your project's secrets, followed by the **Configurations** section.

### Manage project secrets

Manage your project's secrets directly in the **Secrets** tool.
Use **Filter Secrets by name** to find a secret.

**Add a secret**

1. Select **New Secret**.
2. Enter a **Key**, the name of the secret, and a **Value**, the secret itself.
3. Select **Add Secret** to save the entry.

<Frame caption="Add a secret with a key and value. Existing secret names are redacted.">
  <img src="https://mintcdn.com/replit/fAZUw0LJRyEUb1kI/images/workspace/secrets-add.png?fit=max&auto=format&n=fAZUw0LJRyEUb1kI&q=85&s=2fae817bed602f7e1aad02934e0c0990" alt="New Secret form with GOOGLE_API_KEY as an example key, an empty Value field, and the Add Secret button" width="2488" height="1412" data-path="images/workspace/secrets-add.png" />
</Frame>

**Edit a secret**

1. Select the <img class="icon-svg" src="https://mintcdn.com/replit/X_IP1EeHGm0cA2VA/images/icons/vertical-dots.svg?fit=max&auto=format&n=X_IP1EeHGm0cA2VA&q=85&s=7b4b6a9992b3b20202297b60b6ef416d" alt="three vertical dots icon" height="16" width="16" data-path="images/icons/vertical-dots.svg" /> vertical dots menu next to the secret.
2. Select **Edit** from the contextual menu.
3. Update the text in the **Key** or **Value** field and select **Update Secret** to save changes or **Cancel** to discard changes.

**View or hide a secret**

To view a secret, select the <img class="icon-svg" src="https://mintcdn.com/replit/rJldsgYVucXB_6kW/images/icons/eye.svg?fit=max&auto=format&n=rJldsgYVucXB_6kW&q=85&s=ef4c8029c7e1a366680367b9aa573029" alt="eye icon" width="16" height="16" data-path="images/icons/eye.svg" /> eye icon next to the secret.

To hide the secret, select the <img class="icon-svg" src="https://mintcdn.com/replit/rJldsgYVucXB_6kW/images/icons/eye-slash.svg?fit=max&auto=format&n=rJldsgYVucXB_6kW&q=85&s=cccbc60ff55d519c89c7b4d2a3e0ee4a" alt="eye with a slash icon" width="16" height="16" data-path="images/icons/eye-slash.svg" /> eye with slash icon.

**Delete a secret**

To delete a secret, select the <img class="icon-svg" src="https://mintcdn.com/replit/X_IP1EeHGm0cA2VA/images/icons/vertical-dots.svg?fit=max&auto=format&n=X_IP1EeHGm0cA2VA&q=85&s=7b4b6a9992b3b20202297b60b6ef416d" alt="three vertical dots icon" height="16" width="16" data-path="images/icons/vertical-dots.svg" /> vertical dots menu next to the secret and select **Delete**.

**Edit secrets in bulk**

Open the vertical dots menu in the **Secrets** header and select **Edit as JSON** or **Edit as .env**.
Review the full list before saving: bulk editing replaces the project's existing secrets.

### Manage account secrets

Account secrets let you reuse credentials across your projects. Manage them in **Account Settings > Account Secrets**.

To link account secrets to a project you own:

1. Open the project's **Secrets** tool.
2. Select the chain-link icon labeled **Link Account Secrets** in the header.
3. Select the checkboxes beside the secrets you want to use.
4. Select **Link to this App**.

Linked secrets stay in sync with your account secrets. To remove a link, open the linked secret's options menu and select **Unlink**.

### Manage configurations

Use the **Configurations** section in the **Secrets** tool for non-sensitive values.

To add a configuration:

1. Select **New configuration**.
2. Enter a **Key**, such as `LOG_LEVEL`, and a **Value**, such as `debug`.
3. Select **Add configuration**.

For a value specific to one environment, select **More** beside **New configuration**, then **New published app configuration** or **New testing configuration**.

<Frame caption="Add a non-sensitive setting in the Configurations section.">
  <img src="https://mintcdn.com/replit/fAZUw0LJRyEUb1kI/images/workspace/configurations-add.png?fit=max&auto=format&n=fAZUw0LJRyEUb1kI&q=85&s=fafcc5a53ac90eb163137fe3bde7c7de" alt="Configurations section with empty Key and Value fields and an Add configuration button" width="2070" height="416" data-path="images/workspace/configurations-add.png" />
</Frame>

<Warning>
  Do not store API keys, passwords, or authentication tokens as configurations. Use secrets for sensitive values.
</Warning>

### Manage production secrets

To find secrets for your published project, open **Publishing**, select **Adjust settings**, and locate **Production app secrets**.
Review the values your published project needs, especially if you use different credentials for testing and production.

### Managing secrets visibility

Secrets visibility depends on your access to a Replit project and whether you authored it.

You can use one of the options to share your Replit project:

* **Multiplayer**: Invite Replit users to collaborate in real-time
* **Cover page**: Show a preview of your Replit project with the option to remix it
* **Remix**: Make your individual or organization's Replit project public so others can create their version

The following table shows secret name and value visibility in the different scenarios:

| Access Method | Who | Can See Names | Can See Values |
| - | - | - | - |
| Multiplayer | Multiplayer collaborator | ✓ | ✓ |
| Multiplayer | Organization member (Owner role) | ✓ | ✓ |
| Multiplayer | Organization member (Non-owner) | ✓ | |
| Cover Page | Any visitor | | |
| Remix | Owner/collaborator remixing own Replit project | ✓ | ✓ |
| Remix | Non-owner/collaborator remixing Replit project | ✓ | |
| Remix | Anyone remixing from cover page | ✓ | |
| Organization Remix | Organization member with Owner role | ✓ | ✓ |
| Organization Remix | Organization member without Owner role | ✓ | |

<Warning>
  Organization members without the Owner role cannot view secret values in a Replit project, but can access their values by printing the environment variables.
</Warning>

## Database related secrets

When you add Replit's Database, the Project Editor automatically creates the following secret:

| Secret | Description |
| - | - |
| `DATABASE_URL` | SQL database connection string |

<Info>
  Legacy Neon development databases may also include `PGHOST`, `PGUSER`, `PGPASSWORD`, `PGDATABASE`, and `PGPORT`. Current Replit development databases use `DATABASE_URL` instead.
</Info>

To view all environment variables in your Replit project, run `printenv` in the Shell Project Editor tool or print them from your code.

## Predefined environment variables

Replit automatically sets the following environment variables that you can access from your project's code:

| Environment Variable | Description |
| - | - |
| `REPLIT_DOMAINS` | Comma-separated list of all domains associated with your Replit project |
| `REPLIT_USER` | Username of the current editor, which may vary in Multiplayer sessions |
| `REPLIT_DEPLOYMENT` | Set to `1` if the code is running in a published project, unset otherwise |
| `REPLIT_DEV_DOMAIN` | Development URL on the `replit.dev` domain, which is different from the Deployment URL |

These are not listed in the Secrets tool, but your project's code can read them like any other environment variable.
