---
title: Workspaces and environments
description: Understand workspace selection and organize environment-specific values.
---

Secrets belong to a Vikings workspace. Each enabled workspace has named environments, and each environment contains named secrets. The same secret name can have different values in `dev` and `prd`.

## Select a workspace

In the dashboard, select the intended workspace before opening Secrets. API tokens belong to one workspace; Secrets API paths contain an environment and secret name, not a workspace parameter. A token cannot switch to another workspace by changing a header or URL.

Workspace selection and environment selection are separate. Choosing `dev` in a request does not restrict the token to `dev`: its selected Secrets permissions cover every environment of its workspace. Use a separate workspace when you need that authorization boundary.

## Enable Secrets

An owner/admin with management permission can enable Secrets for the workspace. The dashboard starts with `dev` and `prd`. The API accepts a custom environment list; an omitted or empty list uses those defaults. Re-enabling an already registered workspace returns `409`.

Enabling Secrets registers the existing workspace; it does not create a new Vikings workspace. Workspace administration belongs to the dashboard's workspace settings.

## Add or remove an environment

Use **Add environment** on the Secrets home page. Pick a descriptive name such as `docs-demo`. The dashboard accepts lowercase letters, digits, hyphens and underscores; `compare` is reserved for the comparison page.

Review the workspace, environment and secret count before confirming deletion. Removing a nonempty environment requires a forced deletion and removes its secrets. Treat deletion as destructive; it is not the way to switch environments or undo an edit.

See [Workspace and environment API](api.md#workspace-and-environments) for exact requests. No environment-rename endpoint is exposed by this API.
