← All guides

8 min

Use secrets and variables

Keep the values a task needs out of the prompt. Variables hold configuration. Secrets hold credentials. The agent never sees a secret in plain text.

5,000 free credits to start.

  1. 01

    Know which one you need

    A variable holds a value you are happy to read in a run transcript. A channel name, a threshold, a sending address. A secret holds anything you are not. An API token, a signing key, a password.

  2. 02

    Store it at the right level

    Put a value the whole organization shares at the organization level. Put a one-off token on the workflow that needs it. The narrowest level that works is the right one.

  3. 03

    Reference it from the prompt

    Name the variable in the prompt and the run resolves it. A secret is injected where it is needed and never lands in the prompt text, so it stays out of the transcript your team reads.

  4. 04

    Rotate without touching a prompt

    The value lives beside the workflow. Rotating a token is one edit in one place. Every workflow that references it picks up the new value on its next run.

  5. 05

    Prefer integrations for credentials

    Connected integrations already inject their credentials at the network layer. The token for Slack or Stripe belongs in the integration.

Try it in your workspace.

Start free, connect a tool, and write the first prompt in plain words.