Repository navigation
Secret card: save the value into the project's .env #16540
shootingallday
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What I want
Let an agent's secret card (
request_secret, added in #15907) save the value into a file in the project, such as.env, instead of only producing a one-usesecretReffor webhook signatures.Why
Most secrets an agent asks me for are app keys: a Stripe key, a Supabase key, a Linear token. The app reads them from
.env. Today the card can't help with any of those, because asecretRefonly feedssignature.secretRefon a scheduled task and expires after 24 hours. So I keep a small CLI that reads hidden input in my terminal and writesNAME=valueinto.env. That needs me at the PC. The card works from my phone, which is where I usually am when an agent needs a key.Smallest version I can think of
An optional target on
request_secret:{ "label": "Stripe secret key", "reason": "...", "saveTo": { "name": "STRIPE_SECRET_KEY", "file": ".env" } }When the user saves the card, the server:
NAME=valueto the file, replacing an existingNAME=line, in one atomic write;fileinside the project's workspace root and refuses anything outside it;{ saved: true, name, file, length, gitignored }and never the value.Everything else stays as it is: the same card, masking, decline, and the answered-once rule. No
secretRefis minted whensaveTois set.Open choice
Where the file lands. I'd write to the project's main workspace root, not the thread's worktree, since worktrees get removed and a key saved there would go with them. A project setup script (or #6905's
.worktreeinclude) can copy.envinto new worktrees.Related
.worktreeincludeAll reactions