When you call the Secrets API or a Browserbase SDK directly, encrypt values locally before creating or updating a Secret. Fetch the project keypair, seal the value with its public key, and send the resulting
sealedSecretValue and keypairId. The Browse CLI performs these steps for you.Use a Secret in a Function
Attach a Secret to a Function, then read it from
context.secrets.Create a Secret
1
Install the Browse CLI
Install or update the CLI:
2
Set your Browserbase API key
Export your API key in the terminal that runs the Browse CLI:Browserbase resolves the project from this API key. You don’t need a Project ID.
3
Create the Secret
Choose the name that your workload will use, then run:When
Secret value: appears, paste the Secret value and press Enter. The terminal does not display the value while you enter it.4
Check the Secret metadata
- Browse CLI
- Node.js
- Python
List your Secrets:Get one Secret by ID:
Update a Secret
Replace the stored value without changing the Secret ID or its Function attachments:Delete a Secret
Delete a Secret by ID:- Browse CLI
- Node.js
- Python
How Browserbase handles Secret values
- The Browse CLI encrypts each value before upload.
- Browserbase stores the encrypted value.
- Get and list operations return metadata only.
- Browserbase exposes a value only to a Function that has the Secret attached.
Next step
Add Secrets to a Function
Attach the Secret, read it in Function code, and test a deployed invocation.