What is secrets management?
An API key in the browser, a password in the repository, a token nobody can rotate: the leaks that need no hacker at all.
In short
Secrets management is the practice of keeping an application's credentials, such as API keys, database passwords, signing keys and OAuth tokens, out of code and out of the browser: stored encrypted, given only to the services that need them, rotated on a schedule or after a leak, and audited so you know who used them.
Also called: API key management, Environment variables
Why it matters when your prototype goes to production
In a prototype it is easy for a key to end up where it should not: pasted into client code so a feature works, committed to the repository, shared in a chat. Anything sent to the browser can be read by anyone who opens the developer tools, and anything in the repository history stays there even after the line is deleted.
The rules
- Secrets live in environment variables or a secrets manager, never in code.
- The browser only ever gets keys designed to be public.
- Each service gets only the secrets it needs.
- Every secret can be rotated without an outage, and is rotated when someone leaves or a leak is suspected.
Rotation is the part most apps cannot do. Zulu's signed links come from one signer with keys on a ring, so a new key signs while the old one still verifies, and rotation is a window rather than an outage.
Common questions
Are environment variables secure?
They keep secrets out of code, which is the first step. On the server they are fine; any variable bundled into the front end is public.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.