> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets management

> Where API keys live, how they're protected, and how to rotate them safely.

Treat every secret as if it'll leak — design for that, and most leaks become non-events.

## The rules

<CardGroup cols={2}>
  <Card title="Never commit to source" icon="x-circle">
    `.gitignore` `.env*`. Use vly's secret store.
  </Card>

  <Card title="Never expose to the client" icon="eye-off">
    Anything in `process.env` is server-only. Only `VITE_*` is client-visible.
  </Card>

  <Card title="Scope per environment" icon="layers">
    Test keys in preview/staging, live keys in production. No mixing.
  </Card>

  <Card title="Use least-privilege keys" icon="key-square">
    A read-only key is much less dangerous if leaked.
  </Card>

  <Card title="Rotate quarterly" icon="repeat">
    Even without suspected compromise. Cheap insurance.
  </Card>

  <Card title="Audit access" icon="scroll-text">
    Review the [audit log](/features/workspace/audit-logs) monthly for unexpected secret reads or changes.
  </Card>
</CardGroup>

## Where vly stores secrets

In an encrypted secret store (AES-256), per-environment, accessible only to server-side code via `process.env`.

See [Deployment → Secrets](/deployment/secrets) for the operational details.

## What to do if a secret leaks

1. Revoke at the provider immediately.
2. Generate a replacement.
3. Update in vly's secret store for affected environments.
4. Audit downstream API logs for unexpected use.
5. Notify users if data was at risk.

## Related

<CardGroup cols={3}>
  <Card title="Deployment → Secrets" icon="lock" href="/deployment/secrets">
    Operational reference.
  </Card>

  <Card title="Environment variables" icon="key-round" href="/deployment/environment-variables">
    The mechanism.
  </Card>

  <Card title="Audit logs" icon="scroll-text" href="/features/workspace/audit-logs">
    Track secret changes.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.