Cloud
Secrets Management
AES-256-GCM authenticated encryption for secrets at rest.
Overview
The secrets manager encrypts and decrypts sensitive values using AES-256-GCM, providing authenticated encryption that protects against both eavesdropping and tampering.
Usage
typescript
Key Generation
Generate a cryptographically secure 32-byte encryption key:
typescript
Store this key in your environment variables or KMS. Never commit it to source control.
Global Singleton
For convenience, a pre-configured singleton is available:
typescript
Note: The singleton auto-generates a random key if none is provided. Secrets will not survive process restarts. Always provide
encryptionKeyin production.
Options
| Option | Type | Description |
|---|---|---|
encryptionKey | string | 64-character hex string (32 bytes). Auto-generated if omitted. |
API Reference
set(name, plaintext)— encrypt and storeget(name)— decrypt and return, ornullhas(name)— check existence without decryptingdelete(name)— remove a secretlist()— enumerate names (values never exposed)SecretsManager.generateKey()— create a new encryption key