Skip to main content

Secrets

Secrets let your agents use credentials, such as a portal password or a vendor API key, without the value ever appearing in a conversation. You store the value once, and agents refer to it by name.
Only Organization Admins (org:admin) can add, rotate, or delete secrets. See Roles & Permissions.

Add a secret

  1. Go to Control Hub → Settings → Secrets.
  2. Click Add secret.
  3. Enter a key in UPPER_SNAKE_CASE, for example SUPPLIER_PORTAL_PASSWORD, and the value.
  4. Click Add.
Values are write-only. Once saved, a secret can’t be viewed again, only rotated (replaced with a new value) or deleted. Keys can be up to 64 characters, and values up to 8,192.

Use a secret

Anywhere an agent passes a value to a tool, it can write {{secret:KEY}} instead of the value:
Click the copy icon next to a secret in Settings to copy its {{secret:KEY}} token. Agents aren’t told which secrets exist. Give them the token: put it in the agent’s instructions (for example, “Log in to the supplier portal with password {{secret:SUPPLIER_PORTAL_PASSWORD}}”) or mention it in the chat.

How values stay hidden

  • In conversations: the agent writes only the {{secret:KEY}} token, so that’s all that is saved in the conversation and in tool-call logs.
  • When a tool runs: Aster swaps in the real value on the server, just before the tool runs.
  • In tool results: if a result contains the value, for example because a script printed it, Aster replaces it with *** before the agent sees it.
Redaction catches the value as written. An agent that deliberately transforms a secret (for example, encodes it before printing) could still reveal it. Secrets stop credentials from leaking into transcripts by accident; they don’t make a value safe from an agent you’ve instructed to expose it.
Secrets belong to your organization and are never available to agents in other organizations.