BuildliyBuildliy
How it worksTemplatesPricing
BuildliyBuildliy

Build apps and websites by chatting with AI. From idea to live product, no code required.

Product

  • Templates
  • Showcase
  • Pricing
  • Changelog

Earn

  • Affiliate program
  • Get your link

Resources

  • Docs
  • Support

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Affiliate terms
  • Security
  • Report an app

© 2026 Buildliy. All rights reserved.

v1.0

Get started

  • Welcome
  • Quick start
  • Create your account
  • Your dashboard
  • Start from a template

Build your app

  • The project workspace
  • Chat with Buildliy
  • Plans and approvals
  • Write great prompts
  • Add images and files
  • Edit by clicking
  • Version history
  • Design and themes
  • Images in your app
  • Project knowledge
  • View and download code
  • How builds are checked

Backend and data

  • The Manage tab
  • Database
  • User sign-in
  • File storage
  • Secrets and API keys
  • Send email
  • AI in your app
  • Logs and errors
  • Use your own backend

Integrations

  • Connectors
  • Take payments
  • GitHub
  • Connect any API

Publish and grow

  • Publish your app
  • Launch checklist
  • Custom domains
  • Password protection
  • Analytics
  • SEO and sharing
  • Hosting
  • Duplicate and transfer

Account and billing

  • Plans
  • Credits and usage
  • Teams
  • Account settings
  • Invite friends

Help

  • Fix problems
  • Security and privacy
  • Keyboard shortcuts
  • Glossary
  • FAQ
  • Get help

Backend and data

Secrets and API keys

Store the private keys your app needs to talk to other services, keep them safe, and understand how they reach your preview and your live app.

A secret is a private value your app needs but nobody else should see. Usually it's an API key or token: the password-like code a service such as a maps, weather or text-message provider gives you so your app can use it.

Secrets aren't part of your app's code. Buildliy stores them separately, encrypted, and hands them to your app's server when it runs. That way they never appear in your code, in GitHub, or in the pages visitors download.

How secrets are kept safe

  • Encrypted when stored. Buildliy encrypts every secret before saving it.
  • Server only. Only your app's server code can read a secret. It's never sent to visitors' browsers.
  • Never shown again. After you save a secret, you can't view its value again, only replace it.
  • Owner only. Only the project's owner can see and change the secrets in Manage → Secrets. A teammate can answer the AI's key card in a shared app, but can't replace a key someone has already saved.

When the AI asks for a key

If a feature you ask for needs a key, the AI pauses and shows a card in the chat. There are two kinds.

A Connect card, for services in Buildliy's Connectors list, such as Resend, Twilio, Airtable or SendGrid. Click Connect with the service's name to add your key. Buildliy checks the key works with the service before saving it, keeps it encrypted, and saves it to your account so you can use it in your other apps too. Once it's connected, the AI picks the build back up. If you've connected the service before but it isn't on for this app yet, the button says Continue with the service's name instead. If it's already connected and on for this app, the AI just uses it and you don't see a card. Skip for now closes the card without connecting anything: the AI replies that you can connect the service any time from the Connectors page, and waits for your next message. See Connectors.

A key card, for any other key. It shows the AI's question, the name the key will be Saved as (for example WEATHER_API_KEY), and a box to paste the key into.

  1. 1

    Get the key from the service

    Sign in to the service's website and copy your API key. The card's question usually says what the key is for.

  2. 2

    Paste it into the card

    Paste the key into the box. Click the eye icon if you want to check what you pasted, and hide it again before you share your screen.

  3. 3

    Click Save

    The key is saved encrypted. As the card says: "Saved securely and encrypted. It never appears in the chat or in your app's code. You can change it later in Manage → Secrets." (Teammates see "The project owner can change it later.") The AI then carries on building with it.

If you click Skip, nothing is saved and the AI carries on without the key. The feature that needs it won't work until you add the key in Manage → Secrets.

Taking payments is set up differently. See Take payments.

Don't paste keys into the chat

Anything you type into the chat box is saved in your conversation and read by the AI, and it isn't hidden or encrypted like a secret. Always use the key card or Manage → Secrets instead.

Warning:

If you pasted a key into the chat by mistake, treat it as exposed. Go to the service's website, create a new key and delete the old one, then save the new key in Manage → Secrets.

Add, change or remove secrets yourself

  1. 1

    Open Secrets

    Open the Manage tab and choose Secrets.

  2. 2

    Fill in Add new secret

    Under Add new secret, enter a Name in capital letters with underscores, like WEATHER_API_KEY, the Value, and an optional Description so you remember what it's for.

  3. 3

    Save it

    Click Save. It appears under Saved secrets.

The name has to match the one your app's code uses. If you're not sure, ask the AI which name it expects.

Prompt
Which secret name does the weather widget read its key from?
  • Change a secret. Click the circular-arrow icon (Rotate this secret), paste the new value, and click Rotate. On wider screens, the Rotations column counts how many times a secret has been rotated.
  • Save over an existing name. Saving a secret with a name that's already saved replaces the old value. Buildliy asks first: your preview switches to the new one right away, and your published app keeps the old one until you publish again. You choose Keep the old one or Replace it.
  • Remove a secret. Click the trash icon (Delete this secret) and confirm. Your app stops being able to use it: your preview right away, and your published app the next time you publish.

Secrets in your preview and your live app

  • Your preview picks up a new, changed or removed secret automatically. You don't need to rebuild.
  • Your published app gets its secrets when you publish. After you change a secret, publish again so your live site uses the new value. When your app is live, the message you see after a change in Manage → Secrets, or after saving a key from a card in the chat, reminds you to re-publish.

Secrets and connectors

Both store keys safely. The difference is where they live and who can use them.

ConnectorSecret
Where it's savedOn your Buildliy accountIn one app
Used byAll your own apps by default (switch it off for one app in Manage → Connectors); an app shared with your team only once you switch it on thereOnly this app
Checked before savingYes, Buildliy tests the key with the serviceNo
Best forServices in the Connectors list that you use in several appsAny other key, or a different key for just one app

If a secret and a connector have the same name, the secret wins for that app. That's an easy way to use a different key in one app.

Keys Buildliy adds for you

Some features add secrets for you. If your app uses AI in your app, you'll see BUILDLIY_API_KEY and BUILDLIY_API_URL. If it takes payments, you'll see BUILDLIY_API_KEY and BUILDLIY_WEBHOOK_SECRET. If it lets visitors upload files or reports its errors, you'll see BUILDLIY_API_KEY and BUILDLIY_API_URL. Don't change or delete them, or those features stop working.

Related

  • Connectors
  • Connect any API
  • Security and privacy
  • Publish your app
PreviousFile storageNextSend email from your app

Still stuck? Read the FAQ or contact us.

On this page

  • How secrets are kept safe
  • When the AI asks for a key
  • Don't paste keys into the chat
  • Add, change or remove secrets yourself
  • Secrets in your preview and your live app
  • Secrets and connectors
  • Keys Buildliy adds for you
  • Related

Ask AI

Answers from the Buildliy docs

How can I help?

Ask anything about building, publishing or paying for your app. Answers come from these docs, with links to the pages they use.

Try asking

AI answers can be wrong. Check the linked page.