Skip to main content
The Secrets tool stores and encrypts secrets, your Replit project’s sensitive information. These include API keys, authentication tokens, and database connection strings that your project uses to connect to external services. For example, your project might need credentials to call a third-party API, connect to an authentication provider, or access a database. When you add a secret, the tool automatically encrypts the data and makes it available to your Replit project as an environment variable. This approach lets you eliminate hard-coding secrets in your code and reduce the risk of exposing them.
Hard-coding secrets in your codebase can lead to accidental exposure in the following scenarios:
  • Sharing your code with others through a public Replit project or copy-paste
  • Checking your code into version control in a public repository
  • Live streaming or screen sharing your code
Use the Secrets tool to confidently share your code without worrying about exposing credentials.
Secrets tool showing masked secret values and a separate Configurations section for non-sensitive information

Secrets and Configurations in the Secrets tool. Project-specific secret names are redacted.

Secrets versus configurations

The Secrets tool has separate sections for secrets and configurations. Both let your project’s code read values as environment variables without hard-coding them. Configurations are useful when a setting differs between testing on Replit and running your published project. Use a secret whenever a value contains credentials or other sensitive data.

Features

Secrets include the following features:
  • Encryption: Protect your secrets using AES-256 encryption at rest and TLS encryption in transit
  • Project-level secrets: Store and manage secrets that are specific to a Replit project
  • Configurations: Manage non-sensitive environment variables alongside your secrets
  • Environment variable access: Access your secrets from your code using environment variables
  • Collaborative access: Share secrets with collaborators and team members

Usage

Secrets are available for all deployment types except Static Deployments.

How to find Secrets

Open the Secrets tool from your project’s tools pane:
  1. Open your project in the Project Editor.
  2. Select Tools at the top to open the tools pane.
  3. Find the Setup section and select Secrets.
Project Editor tools pane with the Tools button at the top and Secrets under the Setup heading

Select Tools, then Secrets under Setup.

The Secrets tool opens with your project’s secrets, followed by the Configurations section.

Manage project secrets

Manage your project’s secrets directly in the Secrets tool. Use Filter Secrets by name to find a secret. Add a secret
  1. Select New Secret.
  2. Enter a Key, the name of the secret, and a Value, the secret itself.
  3. Select Add Secret to save the entry.
New Secret form with GOOGLE_API_KEY as an example key, an empty Value field, and the Add Secret button

Add a secret with a key and value. Existing secret names are redacted.

Edit a secret
  1. Select the three vertical dots icon vertical dots menu next to the secret.
  2. Select Edit from the contextual menu.
  3. Update the text in the Key or Value field and select Update Secret to save changes or Cancel to discard changes.
View or hide a secret To view a secret, select the eye icon eye icon next to the secret. To hide the secret, select the eye with a slash icon eye with slash icon. Delete a secret To delete a secret, select the three vertical dots icon vertical dots menu next to the secret and select Delete. Edit secrets in bulk Open the vertical dots menu in the Secrets header and select Edit as JSON or Edit as .env. Review the full list before saving: bulk editing replaces the project’s existing secrets.

Manage account secrets

Account secrets let you reuse credentials across your projects. Manage them in Account Settings > Account Secrets. To link account secrets to a project you own:
  1. Open the project’s Secrets tool.
  2. Select the chain-link icon labeled Link Account Secrets in the header.
  3. Select the checkboxes beside the secrets you want to use.
  4. Select Link to this App.
Linked secrets stay in sync with your account secrets. To remove a link, open the linked secret’s options menu and select Unlink.

Manage configurations

Use the Configurations section in the Secrets tool for non-sensitive values. To add a configuration:
  1. Select New configuration.
  2. Enter a Key, such as LOG_LEVEL, and a Value, such as debug.
  3. Select Add configuration.
For a value specific to one environment, select More beside New configuration, then New published app configuration or New testing configuration.
Configurations section with empty Key and Value fields and an Add configuration button

Add a non-sensitive setting in the Configurations section.

Do not store API keys, passwords, or authentication tokens as configurations. Use secrets for sensitive values.

Manage production secrets

To find secrets for your published project, open Publishing, select Adjust settings, and locate Production app secrets. Review the values your published project needs, especially if you use different credentials for testing and production.

Managing secrets visibility

Secrets visibility depends on your access to a Replit project and whether you authored it. You can use one of the options to share your Replit project:
  • Multiplayer: Invite Replit users to collaborate in real-time
  • Cover page: Show a preview of your Replit project with the option to remix it
  • Remix: Make your individual or organization’s Replit project public so others can create their version
The following table shows secret name and value visibility in the different scenarios:
Organization members without the Owner role cannot view secret values in a Replit project, but can access their values by printing the environment variables.
When you add Replit’s Database, the Project Editor automatically creates the following secret:
Legacy Neon development databases may also include PGHOST, PGUSER, PGPASSWORD, PGDATABASE, and PGPORT. Current Replit development databases use DATABASE_URL instead.
To view all environment variables in your Replit project, run printenv in the Shell Project Editor tool or print them from your code.

Predefined environment variables

Replit automatically sets the following environment variables that you can access from your project’s code: These are not listed in the Secrets tool, but your project’s code can read them like any other environment variable.