Secrets
Secrets let your agents use credentials, such as a portal password or a vendor API key, without the value ever appearing in a conversation. You store the value once, and agents refer to it by name.Only Organization Admins (
org:admin) can add, rotate, or delete secrets. See Roles & Permissions.Add a secret
- Go to Control Hub → Settings → Secrets.
- Click Add secret.
- Enter a key in UPPER_SNAKE_CASE, for example
SUPPLIER_PORTAL_PASSWORD, and the value. - Click Add.
Use a secret
Anywhere an agent passes a value to a tool, it can write{{secret:KEY}} instead of the value:
{{secret:KEY}} token.
Agents aren’t told which secrets exist. Give them the token: put it in the agent’s instructions (for example, “Log in to the supplier portal with password {{secret:SUPPLIER_PORTAL_PASSWORD}}”) or mention it in the chat.
How values stay hidden
- In conversations: the agent writes only the
{{secret:KEY}}token, so that’s all that is saved in the conversation and in tool-call logs. - When a tool runs: Aster swaps in the real value on the server, just before the tool runs.
- In tool results: if a result contains the value, for example because a script printed it, Aster replaces it with
***before the agent sees it.
Related
- Browser use: log in to websites with secrets
- Roles & Permissions