---
slug: dashboard/secrets
title: Secrets in the dashboard
kind: reference
surface: dashboard
summary: Reference for the Secrets area of the Aetherfy dashboard — adding, listing and deleting agent-scoped and workspace-scoped secrets, what each label means, when a change reaches a running agent, and the afy CLI and REST equivalents.
sources:
  - dashboard/src/app/(authenticated)/dashboard/secrets/page.tsx
  - dashboard/src/app/(authenticated)/dashboard/settings/tabs.tsx
  - dashboard/src/components/ui/TypedConfirmModal.tsx
---

# Secrets in the Aetherfy dashboard

## What the Aetherfy dashboard's Secrets area is

The Secrets area of the Aetherfy dashboard, at
[app.aetherfy.com/dashboard/secrets](https://app.aetherfy.com/dashboard/secrets),
lists every secret on your account and adds or deletes one. An Aetherfy secret is
scoped to one agent or to one workspace, never to the account, which is why this
area is its own sidebar entry and not a Settings tab. How secrets are delivered and
resolved is explained at [Secrets](/agents/secrets).

A secret's value is write-only: the list shows its key, scope and last update,
and the value always masked. Nothing in Aetherfy reads a value back.

## Aetherfy secret labels

| Label | Meaning |
|---|---|
| `agent` | Scoped to one agent, named under the badge. Shown as AGENT |
| `workspace` | Scoped to a workspace and shared by every agent in it, named under the badge. Shown as WORKSPACE |
| `SCOPE HIERARCHY` | The rule beside the list: an agent secret wins over a workspace secret with the same key |
| `No secrets yet.` | The account has no secret |

A change does not reach a machine that already exists: a machine keeps the values
it was created with. A service agent picks a change up on its next deploy — a
**Redeploy** in the [Agents area](/dashboard/agents), `afy redeploy`, `afy deploy`
or a push — and a task agent on its next run.

## Aetherfy secret actions

| Action | CLI | REST |
|---|---|---|
| **INJECT_SECRET** — scope, agent or workspace, key, value, and an optional description shown in the list. Saving an existing key replaces its value | `afy secrets set` ([secrets](/cli/secrets)) | `POST /api/v1/agents/{agent}/secrets`, `POST /api/v1/workspaces/{workspace}/secrets` ([secrets API](/agents/api-secrets)) |
| List | `afy secrets list` | `GET /api/v1/agents/{agent}/secrets`, `GET /api/v1/workspaces/{workspace}/secrets` |
| Delete — type the key to confirm | `afy secrets delete` | `DELETE /api/v1/agents/{agent}/secrets/{key}`, `DELETE /api/v1/workspaces/{workspace}/secrets/{key}` |

A deleted secret cannot be recovered; anything that reads it fails until it is set
again.

## What the Aetherfy dashboard does not do for secrets

| Not in the dashboard | Where instead |
|---|---|
| Show a stored value | Nowhere: Aetherfy never returns a secret value |
| Account-wide secrets | They do not exist in Aetherfy. Use a workspace secret for values several agents share |
| Re-encrypt an agent secret's stored value without changing it | `POST /api/v1/agents/{agent}/secrets/{key}/rotate` ([rotating](/agents/api-secrets)). To change the value, set it again |
| Apply a change to a running service | Deploy it again — see above |
