# Secrets

Managing secrets in the web app.

Source: https://keyenv.dev/docs/web-app/secrets/

The secrets page is where you create, view, and manage your environment variables.

## Viewing Secrets

Secrets are displayed in a list showing:
- **Key**: The environment variable name
- **Value**: Hidden by default (click to reveal)
- **Version**: Current version number
- **Updated**: When it was last modified

## Creating a Secret

1. Click **Add Secret**
2. Enter the key name (e.g., `DATABASE_URL`)
3. Enter the secret value
4. Optionally add a description
5. Click **Save**

### Key Naming Conventions

- Use UPPERCASE with underscores: `DATABASE_URL`, `API_KEY`
- Be descriptive: `STRIPE_SECRET_KEY` vs just `KEY`
- Group related secrets: `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`

## Editing a Secret

1. Click on a secret row to select it
2. Click the edit icon or press Enter
3. Modify the value
4. Click **Save**

Each edit creates a new version, preserving the history.

## Viewing Value

Secret values are hidden by default for security. To view:

1. Click the eye icon next to the value
2. The value is revealed
3. Click the eye icon again to hide it

## Version History

Click on a secret to see its version history:

- Previous values (partially masked)
- Who made each change
- When changes were made

## Deleting a Secret

1. Select the secret
2. Click the delete icon
3. Confirm the deletion

> **Warning**
>
> Deleted secrets cannot be recovered. The version history is also removed.

## Bulk Operations

### Import from .env

1. Click **Import**
2. Paste your `.env` file contents or upload a file
3. Review the secrets to be imported
4. Click **Import**

### Export to .env

1. Click **Export**
2. Download the `.env` file

> **Note**
>
> For automated sync, use the CLI: `keyenv pull` and `keyenv push`
