> ## Documentation Index
> Fetch the complete documentation index at: https://docs.asteragents.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets

> Store passwords and API keys once so agents can use them in tool calls without ever seeing them

# Secrets

Secrets let your agents use credentials, such as a portal password or a vendor API key, without the value ever appearing in a conversation. You store the value once, and agents refer to it by name.

<Note>
  Only **Organization Admins** (`org:admin`) can add, rotate, or delete secrets. See [Roles & Permissions](/settings/roles-permissions).
</Note>

## Add a secret

1. Go to **Control Hub → Settings → Secrets**.
2. Click **Add secret**.
3. Enter a **key** in UPPER\_SNAKE\_CASE, for example `SUPPLIER_PORTAL_PASSWORD`, and the **value**.
4. Click **Add**.

Values are write-only. Once saved, a secret can't be viewed again, only **rotated** (replaced with a new value) or **deleted**. Keys can be up to 64 characters, and values up to 8,192.

## Use a secret

Anywhere an agent passes a value to a tool, it can write `{{secret:KEY}}` instead of the value:

```
fill @e2 '{{secret:SUPPLIER_PORTAL_PASSWORD}}'
```

Click the copy icon next to a secret in Settings to copy its `{{secret:KEY}}` token.

Agents aren't told which secrets exist. Give them the token: put it in the agent's instructions (for example, *"Log in to the supplier portal with password `{{secret:SUPPLIER_PORTAL_PASSWORD}}`"*) or mention it in the chat.

## How values stay hidden

* **In conversations:** the agent writes only the `{{secret:KEY}}` token, so that's all that is saved in the conversation and in tool-call logs.
* **When a tool runs:** Aster swaps in the real value on the server, just before the tool runs.
* **In tool results:** if a result contains the value, for example because a script printed it, Aster replaces it with `***` before the agent sees it.

<Warning>
  Redaction catches the value as written. An agent that deliberately transforms a secret (for example, encodes it before printing) could still reveal it. Secrets stop credentials from leaking into transcripts by accident; they don't make a value safe from an agent you've instructed to expose it.
</Warning>

Secrets belong to your organization and are never available to agents in other organizations.

## Related

* [Browser use](/tools/browser_use): log in to websites with secrets
* [Roles & Permissions](/settings/roles-permissions)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.