Blog / Product

Secrets and Environment Variables Without Pasting Keys in Chat

When the Mythex agent needs an API key, it asks through a secure card instead of the chat box. How project secrets and env vars work, and how to rotate a key.

Mythex Team · 2026-09-29 · 3 min read

Most real apps need at least one secret: a payment provider's key, an email service's key, a key for an AI API. In Mythex you don't paste those into a prompt. When the agent needs one, it shows a secrets request card in the chat, you type the value into the card, and it's stored as a project secret that your app can read — without the key ending up in the conversation.

What it does

Every Mythex project can store environment variables: named values, such as STRIPE_SECRET_KEY, that your app reads when it runs instead of having them written into the code. Secrets are environment variables whose values must stay private.

The same values are available in two places:

  • The sandbox, where the agent builds and runs your app while you work.
  • Your published deployments, where visitors use it.

There are three ways to add them:

  1. The secrets request card, which the agent shows in chat when it needs a key to finish something.
  2. Project settings → Secrets, where you can add or edit values any time.
  3. /secrets in chat, to add or update secrets on request.

Why it helps

The obvious way to give an AI agent a key is to paste it into your message. It works, but the key is then part of your chat history, sitting in plain text next to everything else you've said.

The secrets card keeps the value out of the transcript. You enter it in the card's fields, not the message box, and it's stored as a project secret. The agent carries on with the key available in the sandbox.

Keeping keys in project settings rather than in code has other benefits too:

  • Keys stay out of source control. Your code refers to a key by name; the value lives in project settings.
  • The agent and your running app see the same configuration. No copy that drifts out of date.
  • You can rotate a key without rewriting code. Change the value in settings; the code still reads it by name.

If environment variables are new to you, our guide on what environment variables and secrets are explains the idea from scratch.

How to use the secrets card

  1. Ask for the feature — for example, "send a welcome email when someone signs up".
  2. When the agent needs a key, a secrets request card appears in the chat, listing the value it needs.
  3. Enter the value in the card's fields, not the message box.
  4. Confirm. The value is stored as a project secret.
  5. The agent continues, with the key available in the sandbox.

How to add secrets yourself

  1. Open project settings, then Secrets.
  2. Add keys such as STRIPE_SECRET_KEY, OPENAI_API_KEY, or your own service's credentials.
  3. Ask the agent to read them the standard way for your framework — for example from process.env in a Node app.
  4. Republish if a published app needs the new values.

You can also type /secrets in the chat to add or update them there.

Changing a secret on a published app

A published app picks up secrets when it's published. After you add or change one, publish again so the live deployment gets the new value. Until then, visitors are still using the app with the old configuration.

Security tips

  • Never commit secrets into the repository. Keep them in project settings.
  • Prefer server-only keys for privileged operations. A key that can charge cards or send email belongs in code that runs on the server, not in anything a visitor's browser downloads.
  • If a key ever appears in chat history, rotate it. Create a new key at the provider, revoke the old one, and update the value in project settings. Treat any key that has been pasted into a chat as exposed.

Limits

  • The card only helps if you use it. If you paste a key into the message box anyway, it's in the transcript. Rotate it at the provider and update the stored value.
  • Published apps need a republish to pick up new or changed secrets.
  • Storing a key safely doesn't make every use of it safe. Where the key is used still matters — keep privileged keys on the server side of your app.

For more on keeping an app safe before you share it, see our security checklist for AI-built apps.

The docs have the details: Environment variables and secrets and Secrets in chat.

Keep reading

  • A Landing Page for Every Kind of Business — Search for a booking system for a dental clinic or a website for a bakery and land on a Mythex page written for that business, with a prompt ready to build it.
  • A Private Workspace and a Live Preview for Every Project — Every Mythex project runs in its own private cloud workspace with a live preview beside the chat. How it works, how to use it, and what to expect.
  • Auto-Reload: Keep Your Published App Running When Credits Run Low — Auto-reload buys Mythex credits when your balance runs low, so a long build or a busy published app does not stop at zero. How to set it up, and its limits.
  • Build Mythex Apps from Claude, Cursor or Codex — Mythex runs a remote MCP server: connect Claude, Cursor or Codex, and they code in your Mythex cloud sandbox with a live preview, database and publishing.
  • Checkpoints: Undo Any Change the Agent Makes — After every successful turn, Mythex saves a checkpoint of your project. Revert to any of them in two clicks, or edit an earlier message and try again.
  • Connect Gmail, Google Sheets and Slack to Your App Builder — Mythex Connectors link Gmail, Google Sheets, Slack, Notion and more to the chat agent, with no API keys in your code. How it works, setup, and limits.

Start building free · Templates · Docs