Secrets
Availability: The DevBase runtime and production API are not yet deployed. This page describes the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.
Secrets are workspace-scoped and write-only. Values are encrypted with KMS and never returned after creation or rotation; only metadata is readable. Values are redacted from logs and errors. Deletion prevents new use and requests best-effort cancellation of Jobs that reference the secret.
Secret values, API-key plaintext, webhook signing secrets, and presigned URLs must be treated as sensitive. Do not put them in browser storage, logs, source control, or client-side documentation examples.