# Secrets

URL: https://docs.usestitch.ai/docs/resources/secrets



Managed secrets belong to the active organization. Harness auth, sandbox auth, and
environment bindings reference secret names.

```sh
stitch secrets list
stitch secrets add OPENAI_API_KEY
```

The user must enter the value in their private terminal's hidden prompt.
Never request values in chat, print them, put them in YAML, or pass them as command arguments.
Ask before replacing or deleting existing secrets.

## Schema [#schema]

[Managed secret input](/schema/secrets.json) · [Environment bindings](/schema/environment.json)

Names contain letters, numbers, underscores, or hyphens (1–64 characters).
Values are non-empty and at most 8192 characters. Descriptions are optional.
The input schema describes creation, not a safe output format; never include its `value` in agent logs.

```yaml
execution:
  environmentVariables:
    - key: SERVICE_TOKEN
      source: managed
      secretName: SERVICE_TOKEN
      targets: [harness]
```

Use `targets: [setup]` for setup only, or `[setup, harness]` for both.
Confirm names with `stitch secrets list` before full validation.
