Use the dashboard
Edit secrets, import and export values, compare environments, and inspect history.
Open Secrets with the intended workspace selected. The home page lists registered environments and their secret counts. If no environments are available, an owner or admin can enable Secrets or add an environment.
Edit and save
Open an environment. Search filters its secret rows; sorting, visibility filters, notes and last-updated controls help inspect the list. Use Add secret for a new row. Edit a name, value, type or note, or select a row's Delete action, then choose Save. Discard changes clears staged work.
The Save operation is not an all-or-nothing transaction. Successful items stay applied if another item fails. Read the error, correct the failed items, and retry only what remains. A failed rename also prevents edits aimed at that failed new name.
A type affects what the list displays. Never change a protected secret to Publishable merely to make copying easier: its value becomes visible to metadata readers. Safe handling applies to notes and names too.
Reveal, copy and hide
Protected values remain masked until explicitly retrieved. Reveal shows a value; Copy can retrieve it without showing it in the row. Reveal and export requests are audited. Hiding a value removes it from the visible row, but cannot erase a screenshot, clipboard entry or other copy you already made.
Owner/admin role and value access are required. The API has a separate value permission for automation; see Permissions and tokens.
Import and export
Choose Import secrets from the add menu or the environment actions menu. Import accepts .env text or a JSON object. Review the preview, choose whether to overwrite existing names, and inspect the result for skipped names or errors. Valid items can be imported even when other lines fail.
Examples:
DOCS_EXAMPLE_TOKEN="example-only-not-a-credential"
DOCS_EXAMPLE_REGION="example-region"
{
"DOCS_EXAMPLE_TOKEN": "example-only-not-a-credential",
"DOCS_EXAMPLE_REGION": "example-region"
}
The environment actions menu exports .env, JSON or YAML. Export retrieves the environment's plaintext values; download or copy only when you need all of them. YAML is an export format, not an import format. These formats transfer names and values, not a complete backup of types, notes, history or access controls.
Compare environments
Choose Compare, select two or more environments, then run the comparison. The default compares presence, type and the displayed value. Equal masks do not prove equal protected values.
Reveal values reruns the comparison using actual values and requires value access. This exports each selected environment for comparison and can expose many values at once. Shared comparison links retain the environment selection; they do not grant access or include secret values.
History and activity
Open a secret's history drawer for Version history and Access log. History puts the current version first, followed by earlier versions. Older records may have no recorded author; the person who replaced a version is not necessarily its author.
Restoring a historical version creates a new version. It requires both management and value access for scoped API tokens. Environment activity and per-secret access logs provide recent audit entries; use them to review who accessed or changed a secret. The API reference explains filters and limits.