Skip to content
GlxymeshDocs
glxymesh.com
Select theme
Open console
Reading time 1 min

Secrets and API keys

Store API keys for your Glxymesh MCP tools. Secrets are encrypted at rest, scoped to a project, and passed to its tools as environment variables.

Secrets belong to a project. Every tool in the project receives them as environment variables when it’s called.

In the console, open the project’s Secrets page and add a Key and a Value, for example GITHUB_TOKEN.

  • A key uses letters, digits and underscores, and can’t start with a digit.
  • Saving an existing key replaces its value.
  • Values are encrypted at rest and never shown again. The management API doesn’t return them either.
token := os.Getenv("GITHUB_TOKEN")
if token == "" {
return nil, nil, errors.New("GITHUB_TOKEN is not set for this project")
}

A change takes effect on the next call. You don’t need to push the tool again.

  • Secrets are isolated by organization and project. A tool never sees another project’s secrets.
  • Every tool in the project sees every secret in the project. If some tools must not see a credential, put them in a separate project.
  • The platform’s own environment is never passed to tools. A tool sees only its project’s secrets.

Anything a tool returns goes to the MCP client and then to the model. Never include a secret in a tool result, an error message or a log line.

Secrets that were bound to a host and header in the earlier format are still stored, but tools don’t receive them as environment variables. Re-create each one as a key and value, then delete the old entry.