--agent <agent> with an account login.
1. Choose where the credential belongs
Before storing it, check the agent and workspace withartil auth status.
In a team workspace, members who can access the agent can reveal, change,
and delete its secrets. In a personal workspace, only the owner and clients
authorized to act as the agent have access.
SERVICE_API_KEY.
2. Store the value
In a terminal, omit the value to enter it without showing what you type:SERVICE_API_KEY. It shows who last set the value
and when, keeping the value hidden. Running set again replaces it.
The credential comes from another command
The credential comes from another command
Pipe that command’s output directly into
artil secrets set SERVICE_API_KEY.
This keeps the key out of the command text and shell history.If that command produces JSON, select a field with --json-path .token
or a nested path such as --json-path '.data.items[0].key'.Add --json for JSON output. With this flag, supply or pipe the value;
the CLI returns an error if it would need to prompt for one.The name or value is rejected
The name or value is rejected
Names use letters, digits, and underscores and cannot begin with a digit.
Names such as
PATH and HOME are reserved. Values must contain at least
one character. Multiline values are accepted, but some clients cannot load them.3. Choose where to use it
Linking copies all of the agent’s secrets to the client or file you choose. Link only places that should have access to all of them.artil init already links the local client it connects, so check
artil secrets list before adding another link. The Claude Code plugin and
Pi extension do not link secrets as part of their installation.
- Claude Code
- Hermes
- Project .env
$SERVICE_API_KEY without putting the value
into the conversation.artil secrets list shows the client or file you linked. Fix any
reported linking errors, then run artil secrets pull to try again. Use the
saved key to make a request to the service and check that it succeeds.
Programs that receive a secret through their environment can read its value.
Keep those values out of logs and conversations.
Keep it working
Refresh a changed credential
Refresh a changed credential
set and remove refresh the agent’s linked destinations on this machine.
After changing a value in the app or on another machine, run:pull each time you need changes made elsewhere. Claude Code’s hook
also tries to refresh secrets when a session starts. If the hook is already
active, the next Bash command can use values updated by pull. Restart
other programs that read their environment only at startup.If storing succeeds but updating a linked destination fails, the command
reports the error and exits with a nonzero status. Fix the link and pull again.Paste a credential into a form
Paste a credential into a form
Remove a local link
Remove a local link
./.env with the linked destination, such as claude-code or
hermes. Unlinking removes the values the CLI wrote there and leaves the secret
stored in Artil. Stop processes that already loaded those values if they
should no longer have access.Delete or revoke a credential
Delete or revoke a credential