Manage test secrets
Performance tests usually need credentials: an API token, a service account password, a webhook signing key. Maxoperf keeps these values in project secrets, so they never live in your test files and never appear in run logs.
How project secrets work
Section titled “How project secrets work”- A project secret is a named, encrypted value stored at the project level.
- Each test binds the secrets it needs and maps each one to an environment-variable name.
- At run time, Maxoperf injects those variables into the runner before your test starts.
- The runtime payload is short-lived and belongs to one run.
Create a secret
Section titled “Create a secret”-
Open the project that owns the test and switch to the Secrets tab.
Secrets hub. Pick the workspace vault, then open its secrets page to add a project secret. -
Click New secret. Give it a clear name like
checkout-api-token. -
Paste the value. MaxoPerf encrypts it when you save.
-
Save. The secret appears in the list with the value masked.
To rotate a secret, edit it. New runs use the new value, and nobody can read the previous value any more.
Bind a secret to a test
Section titled “Bind a secret to a test”- Open the test and switch to the Dependencies tab.
- Pick the secret from the picker (grouped by kind, alongside virtual services, tunnels, and browser fleets).
- Type the name suffix the test expects, for example
CHECKOUT_API_TOKEN. MaxoPerf injects it asSECRET_CHECKOUT_API_TOKEN. Leave it empty to use the secret’s own name, upper-cased. - The binding saves immediately — there is no separate save step.
In your test files, read the variable as you would any other. For example:
- Taurus:
${__env(SECRET_CHECKOUT_API_TOKEN)} - k6:
__ENV.SECRET_CHECKOUT_API_TOKEN - JMeter:
${__BeanShell(System.getenv("SECRET_CHECKOUT_API_TOKEN"))}
What never happens
Section titled “What never happens”- MaxoPerf never writes secret values to result pages, run logs, or downloaded artifact bundles.
- Teammates without project-level access never see secret values.
- The runner never logs secret values. Diagnostic output shows only the names of injected variables.
Where to go next
Section titled “Where to go next”- Run your first test: check that the secret binding works end to end.
- Test dependencies: the full picture — secrets alongside virtual services, tunnels, and browser fleets.
- Accounts, workspaces, and projects: review who has access to project secrets.
- Upload test files: keep credentials out of uploaded files.