Skip to content

Store API keys safely with Secrets

In shortSecrets are your app's locked box for API keys and private settings. Add them under Backend → Secrets with a name like WEATHER_API_KEY — they are stored encrypted, never shown again, and read by your app's server code only. Click Apply to preview to use them straight away; the live app gets them the next time you publish. Never paste a key into the chat.

When your app uses another company’s service — a weather forecast, a recipe database, a payment provider — that service gives you an API key: a long secret password that lets your app use your account. Anyone who has the key can use your account, and run up your bill. So keys need a safe place.

That place is Secrets. Each app has its own, stored encrypted. Your app’s code reads the key when it needs it, and nobody — not the people using your app, not the people you share the project with — can see it.

  1. Open your project and click BackendSecrets.

  2. Under Name, type a name for the key, like SPOONACULAR_API_KEY. Use capital letters, digits and underscores; MonstarX turns small letters into capitals for you.

  3. Under Value, paste the key. It shows as dots while you type.

  4. Click Add.

  5. Click Apply to preview, which appears at the top right once you save. The preview restarts with the new key so you can try it at once.

  6. Tell MonstarX in the chat which feature should use it: “use SPOONACULAR_API_KEY to look up nutrition facts for each recipe”.

Your published app gets new and changed secrets the next time you publish. See Publish your app.

Why should I never paste a key into the chat?

Section titled “Why should I never paste a key into the chat?”

The chat is saved with your project. It is shown to everyone you share the project with, read by the AI models that build your app, and kept in your project’s history. A key pasted there is no longer secret. Code that has a key written into it is just as exposed: it ends up in your project’s files, in exports and on GitHub if you connect it.

If you pasted a key somewhere by mistake, make a new key in that service’s dashboard, delete the old one there, and save the new one in Secrets.

  • Change it: type the same name again with the new value. The button says Update instead of Add. Click it, then Apply to preview.
  • Remove it: click the bin next to it and confirm. Parts of your app that used it stop working until you add it again.

Nobody can read a saved value again — not even you. Each one shows as dots with the date it was Added. If you need the key, get it from the service that issued it.

Some names belong to MonstarX or to the system your app runs on, so Secrets refuses them:

  • Names starting with MONSTARX_, BETTER_AUTH_, CLOUDFLARE_, CF_, GCP_, RAILWAY_, NODE_ or NPM_.
  • PATH, HOME, PORT, NODE_ENV, TMPDIR, USER, SHELL, PWD, CI, HOSTNAME, FORCE_COLOR and NO_COLOR.
  • Names starting with VITE_, because those would be built into the page where every visitor can read them. (An imported app that already uses VITE_ names can keep them.)

A name must start with a letter and be at most 64 characters.

Some values are meant to be seen, like a site name or a publishable key that a service says is safe in the browser. Name those starting with PUBLIC_. They can reach the page, and MonstarX warns you as you type the name.

Who can see my secrets?

Nobody can read a saved value, including you. People you share the project with do not see the Backend tab at all. Only your app's server code reads the values.

I added a key but my app still says it is missing.

Click Apply to preview so the preview restarts with it. For the live app, publish again. Also check the name matches exactly what the app reads.

Why can I not see the value I saved?

Values are never shown again once saved, so they cannot leak from your screen. To change one, save the same name with a new value.

Can my app use a secret in the browser?

No. Secrets are read by your app's server code only, so they never reach a visitor's browser. A value the page itself needs, like a publishable key, gets a PUBLIC_ name.

What is the difference between Secrets and Connectors?

Connectors are ready-made forms for well-known services that save their keys into Secrets under fixed names and teach MonstarX how to use them. Secrets is for everything else.