Secrets and API keys
Store API keys for your Glxymesh MCP tools. Secrets are encrypted at rest, scoped to a project, and passed to its tools as environment variables.
Secrets belong to a project. Every tool in the project receives them as environment variables when it’s called.
Add a secret
Section titled “Add a secret”In the console, open the project’s Secrets page and add a Key and a Value, for example
GITHUB_TOKEN.
- A key uses letters, digits and underscores, and can’t start with a digit.
- Saving an existing key replaces its value.
- Values are encrypted at rest and never shown again. The management API doesn’t return them either.
Read it in a tool
Section titled “Read it in a tool”token := os.Getenv("GITHUB_TOKEN")if token == "" { return nil, nil, errors.New("GITHUB_TOKEN is not set for this project")}A change takes effect on the next call. You don’t need to push the tool again.
- Secrets are isolated by organization and project. A tool never sees another project’s secrets.
- Every tool in the project sees every secret in the project. If some tools must not see a credential, put them in a separate project.
- The platform’s own environment is never passed to tools. A tool sees only its project’s secrets.
Keep them out of responses
Section titled “Keep them out of responses”Anything a tool returns goes to the MCP client and then to the model. Never include a secret in a tool result, an error message or a log line.
Secrets from the earlier format
Section titled “Secrets from the earlier format”Secrets that were bound to a host and header in the earlier format are still stored, but tools don’t receive them as environment variables. Re-create each one as a key and value, then delete the old entry.