close
Share feedback
Answers are generated based on the documentation.

sbx secret

DescriptionManage stored secrets
Usagesbx secret COMMAND

Description

Manage stored secrets for sandbox environments.

SERVICE SECRETS (e.g. "github", "anthropic", "openai") When a sandbox starts, the proxy uses stored secrets to authenticate API requests on behalf of the agent. The secret is never exposed directly. Scoped globally (shared across all sandboxes) or to a specific sandbox.

REGISTRY SECRETS (e.g. "ghcr.io", "myregistry.azurecr.io") Used to pull private template images and kit artifacts before sandbox creation. Unlike service secrets, registry credentials are host-only by default. They are not injected into sandboxes unless --all-sandboxes or --sandbox is set (the credential never enters the sandbox filesystem). Use "sbx secret set --registry --password-stdin" to store them.

Commands

CommandDescription
sbx secret importImport secrets detected in host environment variables
sbx secret lsList stored secrets
sbx secret rmRemove a secret
sbx secret setCreate or update a secret
sbx secret set-customexperimental Create or update a custom secret

Global options

OptionDefaultDescription
-D, --debugEnable debug logging