Skip to content

Secrets

Manage secrets and schedules.

Secrets are encrypted key-value pairs stored per workspace. Use them to inject credentials, tokens, and other sensitive strings into test runs without hard-coding values in test scripts. After you create a secret, no API or UI returns its value. You only see the secret name and metadata (version number, last-updated timestamp).

Secrets are workspace-scoped. Each workspace has its own isolated vault, so tests running in Workspace B cannot see a secret in Workspace A.

Click Secrets in the left sidebar. If a workspace is selected in the top-bar scope switcher, the Secrets link opens that workspace’s vault at /workspaces/:workspaceId/secrets. If no workspace is selected, it opens the account-wide Secrets hub at /secrets, where you pick a workspace vault.

Secrets hub: select a workspace to open its encrypted vault. Secrets are scoped per workspace.

The workspace secrets vault lists every secret stored in the workspace. Each row shows:

  • Name: the key you reference in your test environment configuration (e.g., STRIPE_SECRET).
  • Version: goes up by one each time you rotate (update) the value. Check it to confirm a rotation landed.
  • Last updated: the timestamp of the most recent create or rotate operation.

The list never displays a secret value. From the UI, the vault is append-and-rotate only: values go in and never come back out.

  1. Navigate to the workspace vault (via Secrets in the sidebar, or /workspaces/:workspaceId/secrets).
  2. Click Create secret in the page header. A dialog opens.
  3. Enter a Name for the secret. Use a descriptive uppercase name (e.g., PAYMENT_API_KEY, DATABASE_CREDENTIAL). Names must be unique within the workspace.
  4. Enter the Value in the masked password field. The value is not stored in browser history or shown as plain text.
  5. Click Save secret. The dialog closes and a toast confirms “Secret created (value stored encrypted; never shown again).”
  6. The new secret appears in the vault list with version 1.

Rotating a secret replaces its value and bumps the version number. Tests that reference the secret by name pick up the new value on their next run.

  1. In the workspace vault list, find the secret you want to rotate.
  2. Click Rotate value. An inline input field appears next to the secret row.
  3. Enter the new value in the masked input.
  4. Click Save. A toast confirms “Secret value rotated (version bumped).” The version number in the row increments.
  5. Click Cancel at any point to discard your change.
  1. In the vault list, find the secret to delete.
  2. Click Delete. A confirmation dialog appears: “Delete secret <name>? Tests lose bindings to it.”
  3. Confirm the deletion. The secret is removed from the vault immediately.

Secrets are injected into test runs as environment variables. You bind a secret to an environment variable name on the test’s Dependencies tab. At run start, the runner injects the secret value into the process environment.

How to bind a secret to a test:

  1. Open the test you want to configure in the Tests list.
  2. Go to the Dependencies tab of the test detail page.
  3. Pick the secret from the picker (grouped by kind, alongside virtual services, tunnels, and browser fleets), then type the name suffix the test expects. MaxoPerf always prefixes it with SECRET_: a suffix of PAYMENT_API_KEY injects SECRET_PAYMENT_API_KEY, and an empty suffix uses the secret’s own name, upper-cased.
  4. Run the test. The runner injects the secret value as the named environment variable. The value is never logged or surfaced in run outputs.

  • Workspace scope is strict. A test cannot reference a secret from a different workspace, even in the same account. Create the secret in each workspace that needs it.
  • Names are case-sensitive. SECRET_DATABASE_CREDENTIAL and SECRET_database_credential are two different bindings. The SECRET_ prefix is required (bound names must match ^SECRET_[A-Za-z0-9_]{1,120}$); the Dependencies tab upper-cases the suffix, so the name is SCREAMING_SNAKE_CASE.
  • Versions help audit rotations. The version counter shows how many times a secret has been rotated. Check it after a rotation to confirm the update landed.
  • No bulk export. The console cannot export secret values in bulk. If you need a backup, keep your secrets in an external secrets manager and treat the MaxoPerf vault as a mirror.
  • Workspace editor role required. Only members with workspace editor (or higher) permissions can create, rotate, or delete secrets. Viewers can see secret names but not values or the create/rotate/delete controls.