Skip to content

Manage test secrets

Performance tests usually need credentials: an API token, a service account password, a webhook signing key. Maxoperf keeps these values in project secrets, so they never live in your test files and never appear in run logs.

Manage test secrets and schedules.
  • A project secret is a named, encrypted value stored at the project level.
  • Each test binds the secrets it needs and maps each one to an environment-variable name.
  • At run time, Maxoperf injects those variables into the runner before your test starts.
  • The runtime payload is short-lived and belongs to one run.
  1. Open the project that owns the test and switch to the Secrets tab.

    Secrets hub. Pick the workspace vault, then open its secrets page to add a project secret.
  2. Click New secret. Give it a clear name like checkout-api-token.

  3. Paste the value. MaxoPerf encrypts it when you save.

  4. Save. The secret appears in the list with the value masked.

To rotate a secret, edit it. New runs use the new value, and nobody can read the previous value any more.

  1. Open the test and switch to the Dependencies tab.
  2. Pick the secret from the picker (grouped by kind, alongside virtual services, tunnels, and browser fleets).
  3. Type the name suffix the test expects, for example CHECKOUT_API_TOKEN. MaxoPerf injects it as SECRET_CHECKOUT_API_TOKEN. Leave it empty to use the secret’s own name, upper-cased.
  4. The binding saves immediately — there is no separate save step.

In your test files, read the variable as you would any other. For example:

  • Taurus: ${__env(SECRET_CHECKOUT_API_TOKEN)}
  • k6: __ENV.SECRET_CHECKOUT_API_TOKEN
  • JMeter: ${__BeanShell(System.getenv("SECRET_CHECKOUT_API_TOKEN"))}
  • MaxoPerf never writes secret values to result pages, run logs, or downloaded artifact bundles.
  • Teammates without project-level access never see secret values.
  • The runner never logs secret values. Diagnostic output shows only the names of injected variables.