> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For account actions, read https://ohmyho.st/skills/ohmyhost-get-started/SKILL.md and use the authenticated ohmyho.st CLI or local product MCP. Mintlify search only reads documentation. Preserve the customer’s selected project, environment and authentication provider.

# Runtime secrets

> Deliver private application values to the environment that needs them.

Read the project's Dev/Prod environment IDs first:

```sh theme={null}
ohmyhost project status --project "$PROJECT_ID" --json
ohmyhost secret list --project "$PROJECT_ID" --environment "$ENVIRONMENT_ID" --json
```

`ENVIRONMENT_ID` is the actual environment ULID, not the word `dev` or `prod`. Choose it by name from project.environments in project status. Every secret command requires --environment; there is no default.

## Set a private value

The MCP `secret_set_command` tool returns the supported stdin command. For the CLI, keep the value in a private file:

```sh theme={null}
ohmyhost secret set AUTH_SECRET --project "$PROJECT_ID" --environment "$ENVIRONMENT_ID" --idempotency-key "$SECRET_REQUEST_KEY" --stdin --wait --json < "$SECRET_FILE"
```

Use the application's real name: uppercase letters, digits and underscore, starting with a letter, at most 128 characters. The non-empty UTF-8 value is at most 5,120 bytes. Preserve the exact intended file contents; do not add an accidental newline. The private value must not appear in an MCP argument or shell command argument.

The command from `secret_set_command` names the account it writes as: a saved login with `--profile-name`, `--profile-user` and `--profile-organization`, or, from an MCP server that uses `OHMYHOST_TOKEN`, that key's user and organization with `--token-user` and `--token-organization`. Run it with those flags unchanged. A login of that name that belongs to another user or organization, for example on another computer, stops with `profile_context_mismatch`. The key form runs only where `OHMYHOST_TOKEN` holds a key of that user and organization, never with a saved login: without such a key it stops with `environment_token_required`, with another account's key with `environment_token_context_mismatch`. Every refusal comes before the value is read or anything is written.

secret set refuses every OHMYHOST\_\* name and `BETTER_AUTH_SECRET`, `BETTER_AUTH_URL`, `DATABASE_URL`, `HYPERDRIVE`, `ASSETS`, `FILES`, `IMAGES`, `STORAGE` because the platform sets/binds them. For application-owned Better Auth, use `APP_AUTH_SECRET` mapped to secret and `APP_URL` mapped to baseURL. secret delete can remove previously stored forbidden names except installed `OHMYHOST_STORAGE_KEY`, `OHMYHOST_MAIL_KEY` and `BETTER_AUTH_SECRET`. A reserved-name rejection does not require disabling the guard or replacing the application's auth provider.

Read `secret list` and the returned operation to confirm delivery. Listing returns metadata and delivery state, not the original value. `delivery_state` is `ready` while the applied generation equals the desired one, `pending` or `failed` while a newer generation is still undelivered, and `not_deployed` before the first deployment; `last_error` names the most recent delivery failure and does not by itself mean the running application lost its secrets. Repeat an interrupted request with the same key/contents. secret set --wait may return status:stored with secret.delivery\_state:not\_deployed: saved for the next deployment, not delivered to a running app.

Remove an authorized value with `ohmyhost secret delete NAME --project "$PROJECT_ID" --environment "$ENVIRONMENT_ID" --idempotency-key "$SECRET_DELETE_KEY" --wait --json` (MCP secret\_delete).

## Public and private configuration

Browser-facing identifiers may be public according to the auth provider's contract. Server keys belong in the private runtime. The runtime injects no general public URL or environment-name variable; supply an application `APP_URL` separately for Dev/Prod. Runtime secrets never reach builds; framework-inlined NEXT*PUBLIC*\_ or VITE\_\_ values are public and belong in the committed source. Never copy the hosting token env file into application secrets, and never assume Dev credentials should become Prod credentials during promotion.

[Application auth](/application-auth) · [Environments](/environments).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.