Secrets and Environment Variables Without Pasting Keys in Chat
When the Mythex agent needs an API key, it asks through a secure card instead of the chat box. How project secrets and env vars work, and how to rotate a key.
Mythex Team · · 3 min read
Most real apps need at least one secret: a payment provider's key, an email service's key, a key for an AI API. In Mythex you don't paste those into a prompt. When the agent needs one, it shows a secrets request card in the chat, you type the value into the card, and it's stored as a project secret that your app can read — without the key ending up in the conversation.
What it does
Every Mythex project can store environment variables: named values, such as STRIPE_SECRET_KEY, that your app reads when it runs instead of having them written into the code. Secrets are environment variables whose values must stay private.
The same values are available in two places:
- The sandbox, where the agent builds and runs your app while you work.
- Your published deployments, where visitors use it.
There are three ways to add them:
- The secrets request card, which the agent shows in chat when it needs a key to finish something.
- Project settings → Secrets, where you can add or edit values any time.
/secretsin chat, to add or update secrets on request.
Why it helps
The obvious way to give an AI agent a key is to paste it into your message. It works, but the key is then part of your chat history, sitting in plain text next to everything else you've said.
The secrets card keeps the value out of the transcript. You enter it in the card's fields, not the message box, and it's stored as a project secret. The agent carries on with the key available in the sandbox.
Keeping keys in project settings rather than in code has other benefits too:
- Keys stay out of source control. Your code refers to a key by name; the value lives in project settings.
- The agent and your running app see the same configuration. No copy that drifts out of date.
- You can rotate a key without rewriting code. Change the value in settings; the code still reads it by name.
If environment variables are new to you, our guide on what environment variables and secrets are explains the idea from scratch.
How to use the secrets card
- Ask for the feature — for example, "send a welcome email when someone signs up".
- When the agent needs a key, a secrets request card appears in the chat, listing the value it needs.
- Enter the value in the card's fields, not the message box.
- Confirm. The value is stored as a project secret.
- The agent continues, with the key available in the sandbox.
How to add secrets yourself
- Open project settings, then Secrets.
- Add keys such as
STRIPE_SECRET_KEY,OPENAI_API_KEY, or your own service's credentials. - Ask the agent to read them the standard way for your framework — for example from
process.envin a Node app. - Republish if a published app needs the new values.
You can also type /secrets in the chat to add or update them there.
Changing a secret on a published app
A published app picks up secrets when it's published. After you add or change one, publish again so the live deployment gets the new value. Until then, visitors are still using the app with the old configuration.
Security tips
- Never commit secrets into the repository. Keep them in project settings.
- Prefer server-only keys for privileged operations. A key that can charge cards or send email belongs in code that runs on the server, not in anything a visitor's browser downloads.
- If a key ever appears in chat history, rotate it. Create a new key at the provider, revoke the old one, and update the value in project settings. Treat any key that has been pasted into a chat as exposed.
Limits
- The card only helps if you use it. If you paste a key into the message box anyway, it's in the transcript. Rotate it at the provider and update the stored value.
- Published apps need a republish to pick up new or changed secrets.
- Storing a key safely doesn't make every use of it safe. Where the key is used still matters — keep privileged keys on the server side of your app.
For more on keeping an app safe before you share it, see our security checklist for AI-built apps.
The docs have the details: Environment variables and secrets and Secrets in chat.