Backend and data
Secrets and API keys
Store the private keys your app needs to talk to other services, keep them safe, and understand how they reach your preview and your live app.
A secret is a private value your app needs but nobody else should see. Usually it's an API key or token: the password-like code a service such as a maps, weather or text-message provider gives you so your app can use it.
Secrets aren't part of your app's code. Buildliy stores them separately, encrypted, and hands them to your app's server when it runs. That way they never appear in your code, in GitHub, or in the pages visitors download.
How secrets are kept safe
- Encrypted when stored. Buildliy encrypts every secret before saving it.
- Server only. Only your app's server code can read a secret. It's never sent to visitors' browsers.
- Never shown again. After you save a secret, you can't view its value again, only replace it.
- Owner only. Only the project's owner can see and change the secrets in Manage → Secrets. A teammate can answer the AI's key card in a shared app, but can't replace a key someone has already saved.
When the AI asks for a key
If a feature you ask for needs a key, the AI pauses and shows a card in the chat. There are two kinds.
A Connect card, for services in Buildliy's Connectors list, such as Resend, Twilio, Airtable or SendGrid. Click Connect with the service's name to add your key. Buildliy checks the key works with the service before saving it, keeps it encrypted, and saves it to your account so you can use it in your other apps too. Once it's connected, the AI picks the build back up. If you've connected the service before but it isn't on for this app yet, the button says Continue with the service's name instead. If it's already connected and on for this app, the AI just uses it and you don't see a card. Skip for now closes the card without connecting anything: the AI replies that you can connect the service any time from the Connectors page, and waits for your next message. See Connectors.
A key card, for any other key. It shows the AI's question, the name the key will be Saved as (for example WEATHER_API_KEY), and a box to paste the key into.
Get the key from the service
Sign in to the service's website and copy your API key. The card's question usually says what the key is for.
Paste it into the card
Paste the key into the box. Click the eye icon if you want to check what you pasted, and hide it again before you share your screen.
Click Save
The key is saved encrypted. As the card says: "Saved securely and encrypted. It never appears in the chat or in your app's code. You can change it later in Manage → Secrets." (Teammates see "The project owner can change it later.") The AI then carries on building with it.
If you click Skip, nothing is saved and the AI carries on without the key. The feature that needs it won't work until you add the key in Manage → Secrets.
Taking payments is set up differently. See Take payments.
Don't paste keys into the chat
Anything you type into the chat box is saved in your conversation and read by the AI, and it isn't hidden or encrypted like a secret. Always use the key card or Manage → Secrets instead.
If you pasted a key into the chat by mistake, treat it as exposed. Go to the service's website, create a new key and delete the old one, then save the new key in Manage → Secrets.
Add, change or remove secrets yourself
Open Secrets
Open the Manage tab and choose Secrets.
Fill in Add new secret
Under Add new secret, enter a Name in capital letters with underscores, like
WEATHER_API_KEY, the Value, and an optional Description so you remember what it's for.Save it
Click Save. It appears under Saved secrets.
The name has to match the one your app's code uses. If you're not sure, ask the AI which name it expects.
Which secret name does the weather widget read its key from?
- Change a secret. Click the circular-arrow icon (Rotate this secret), paste the new value, and click Rotate. On wider screens, the Rotations column counts how many times a secret has been rotated.
- Save over an existing name. Saving a secret with a name that's already saved replaces the old value. Buildliy asks first: your preview switches to the new one right away, and your published app keeps the old one until you publish again. You choose Keep the old one or Replace it.
- Remove a secret. Click the trash icon (Delete this secret) and confirm. Your app stops being able to use it: your preview right away, and your published app the next time you publish.
Secrets in your preview and your live app
- Your preview picks up a new, changed or removed secret automatically. You don't need to rebuild.
- Your published app gets its secrets when you publish. After you change a secret, publish again so your live site uses the new value. When your app is live, the message you see after a change in Manage → Secrets, or after saving a key from a card in the chat, reminds you to re-publish.
Secrets and connectors
Both store keys safely. The difference is where they live and who can use them.
| Connector | Secret | |
|---|---|---|
| Where it's saved | On your Buildliy account | In one app |
| Used by | All your own apps by default (switch it off for one app in Manage → Connectors); an app shared with your team only once you switch it on there | Only this app |
| Checked before saving | Yes, Buildliy tests the key with the service | No |
| Best for | Services in the Connectors list that you use in several apps | Any other key, or a different key for just one app |
If a secret and a connector have the same name, the secret wins for that app. That's an easy way to use a different key in one app.
Keys Buildliy adds for you
Some features add secrets for you. If your app uses AI in your app, you'll see BUILDLIY_API_KEY and BUILDLIY_API_URL. If it takes payments, you'll see BUILDLIY_API_KEY and BUILDLIY_WEBHOOK_SECRET. If it lets visitors upload files or reports its errors, you'll see BUILDLIY_API_KEY and BUILDLIY_API_URL. Don't change or delete them, or those features stop working.
Related
Still stuck? Read the FAQ or contact us.