Secrets
Store tokens and keys once, then use them in environments and MCP servers without putting them in git.
A secret is a named value, such as an npm token or an API key, stored in your account. Environments refer to it by name, so the value never appears in git.
Add a secret
- Dashboard: open Environments > Secrets and choose New secrets.
- CLI:
ellipsis variable set NPM_TOKEN=your-token-value, orellipsis variable set -f .envto load a file. - API:
PUT /v1/secrets:
Shell
1
curl -X PUT https://api.ellipsis.dev/v1/secrets -H "Authorization: Bearer $ELLIPSIS_API_TOKEN" -H "Content-Type: application/json" -d '{"secrets": [{"name": "NPM_TOKEN", "value": "your-token-value"}]}'
Setting an existing name replaces its value. Names use letters, digits, and underscores, and can't start with a digit. An account can store up to 500 secrets.
Use a secret
List its name under variables without a value:
.ellipsis/environments/private-packages.yaml
1
ellipsis:
2
kind: environment
3
name: private-packages
4
5
repositories:
6
- name: web-repo
7
8
variables:
9
- name: NPM_TOKEN
Setup scripts and the agent get NPM_TOKEN as an environment variable. A missing secret fails the session.
To pass a secret to an MCP server, write ${NAME} in its headers or env. It doesn't need a variables entry.
Rules
- Secrets belong to the account, so any environment can use them.
- Stored values can't be read back through the dashboard, CLI, or API; you see names only.
- The agent can read every secret its environment sets. Keep values out of prompts and command output; see Permissions.
- Delete a secret in the dashboard, with
ellipsis variable delete NPM_TOKEN, or withDELETE /v1/secrets/{name}.