
Understanding a secret prompt
When the agent needs a key, it shows an Add secret card in the chat. The value you type is stored as an encrypted secret and is never shown to the AI. Before entering a value, check:- The secret name, for example
RESEND_API_KEYorOPENAI_API_KEY. This is the exact name your Edge Function reads. - The message before the card. The agent explains what the key is for and where to find it.
- The provider’s dashboard. If you aren’t sure which value to paste, open the provider’s site (Resend, OpenAI, Twilio, and so on) and find the key with the same name.
Manage secrets
To manage a project’s secrets yourself, open the project name menu in the editor, select Project settings, then select Secrets. The list shows each secret’s name and when it was last updated. Values are never shown.- Add secret opens a dialog where you can enter one or more name and value pairs. Select Add another for more rows. Names are saved in upper case and must start with a letter or underscore and contain only letters, numbers, and underscores.
- Delete removes a secret after you confirm. This can’t be undone. If a feature still needs the value, it stops working until you add it again.
- To change a value, add the secret again with the same name. Secrets are write-only, so a value can be replaced but never read back. If you lose a key, generate a new one at the service that issued it.
Where secrets go
Secrets are stored in Vibely’s encrypted secret store and are never written into your project’s files. That means connecting the project to GitHub, exporting it, or downloading it can’t expose them. Before each Edge Function deploy, Vibely pushes your secrets to your linked Supabase project’s Edge Function secret store, where your functions read them:Workspace secrets
Owners and admins can also set secrets for the whole workspace in Settings → Build secrets, in the Secrets card at the top. A workspace secret is available to every project in the workspace, the same way a project secret is. If a project secret has the same name, the project value wins for that project.Secrets vs. public environment variables
Secrets are for server-side values only. Anything with a public prefix is compiled into the app bundle that every visitor downloads:- Use Secrets for
STRIPE_SECRET_KEY,RESEND_API_KEY,OPENAI_API_KEY, and anything else that must never reach a browser or phone. - Use
.envfor values that are public by design, such as a Supabase anon key or a Stripe publishable key. The agent writes these to your project’s.envfile, where you can see them in the code editor.
VITE_STRIPE_SECRET_KEY would be published inside your app’s JavaScript. If you’re tempted to add a public prefix to something called ..._SECRET_KEY, that’s the sign the call belongs in an Edge Function.
Reserved names
Names starting with these prefixes are managed by Vibely and can’t be created or overwritten:SUPABASE_: for exampleSUPABASE_URL,SUPABASE_ANON_KEY, andSUPABASE_SERVICE_ROLE_KEY, set from your linked Supabase project.VIBELY_: for exampleVIBELY_AI_KEYandVIBELY_AI_URL, which your app’s Vibely AI features use.
Deno.env.get("SUPABASE_SERVICE_ROLE_KEY").
FAQ
Can I view a secret's value after saving it?
Can I view a secret's value after saving it?
No. Secrets are write-only. You can replace or delete a secret, but never read its value back.
Are secrets copied when someone remixes my project?
Are secrets copied when someone remixes my project?
No. A remix copies project files only, and secrets are never in the files. Workspace secrets and connected services aren’t copied either.
Should Stripe keys go through this form?
Should Stripe keys go through this form?
Stripe has its own connection flow that validates the key format. Ask the agent to add payments and it opens the Stripe form. See Stripe.
Should my API key go in a secret or in .env?
Should my API key go in a secret or in .env?
If the value must stay private (payment keys, AI provider keys, service credentials), use a secret. If it has a
VITE_ or EXPO_PUBLIC_ prefix and is safe to be public, it belongs in .env.Related
Build secrets
Workspace credentials for package installs and builds.
Supabase
The backend your Edge Functions run on.
Security best practices
Where secrets belong, and what a leaked key means.
Connectors
Services that connect with an account instead of a key.