> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browserbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets

> Store encrypted credentials and make them available only to the Browserbase Functions that need them.

Browserbase Secrets stores credentials that your Functions need at runtime. Create a Secret once, attach it to a Function, and read the value from `context.secrets` when an invocation starts.

Use Secrets for values such as third-party API tokens, service credentials, and other sensitive configuration that should not live in Function code.

## How Secrets work

1. The Browse CLI gets your project's public key and encrypts the value on your machine.
2. Browserbase stores the encrypted value and returns a Secret ID.
3. You attach the Secret ID to a Function.
4. Browserbase loads the attached value into `context.secrets` when an invocation starts.

A Function can read only the Secrets attached to it. Function Secrets are not environment variables and are not available through `process.env` in a deployed invocation.

## Access model

| Action | Behavior |
| - | - |
| Create | Stores an encrypted value under a name such as `SERVICE_TOKEN`. |
| Get or list | Returns the Secret ID and name, never the stored value. |
| Attach | Grants one Function access on its next invocation. |
| Update | Replaces the value while keeping the Secret ID and Function attachments. |
| Detach | Removes one Function's access without deleting the Secret. |
| Delete | Deletes the Secret and removes all of its Function attachments. |

Secrets and Functions must belong to the same Browserbase project. Browserbase resolves the project from the API key used for each command or SDK request.

## Secrets and invocation parameters

Use a Secret for a sensitive value that a Function needs across invocations. Use [invocation parameters](/platform/functions/invoke#pass-parameters) for non-sensitive input that changes from one invocation to the next.

For local development, use a local environment variable as a fallback. Function attachments apply only to deployed invocations.

## Next steps

<CardGroup cols={2}>
  <Card title="Get started with Secrets" icon="key" href="/platform/secrets/getting-started">
    Create, inspect, update, and delete a Secret.
  </Card>

  <Card title="Use Secrets in Functions" icon="bolt" href="/platform/functions/secrets">
    Attach a Secret and read it from Function code.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.