Control and security

Your bots use the token. They never see it.

Secrets in Brainwrite are tokens your bots can use without ever seeing the value. A bot names the secret, and Brainwrite inserts the real value into the request only when it sends it, only to the one https site you allow. The value stays in your computer's secure store, never follows a redirect, and is cleaned out of anything the site sends back.

Publish a changelog entry

Post this release note and its cover image to our changelog hub.

Your Chief of Staff put a team on it

  • Atlas· Rigel, QA and Release Engineer
  • Sage· Ada, Tech Lead
  • Dash· Lin and Pixel, Backend and Frontend Engineers
  • This needs CHANGELOG_INGEST_TOKEN, sent only to https://changelog.northwind.example.
  • Showed a Secret needed card and waited.
  • Posted the entry and its 1.2 MB cover image.
  • The token never appeared in this chat.

DoneSave the token in the Secret needed card: waiting for your yes.

An illustrated example. Your team works on your own files and apps.
A woman works at a lamplit home desk in the evening while Nova, an illustrated AI agent, waits with a page for her approval.
NovaChief of Staff
9:02 am

Publish a changelog entry: done. One thing waits for you.

  1. 1This needs CHANGELOG_INGEST_TOKEN, sent only to https://changelog.northwind.example.
  2. 2Showed a Secret needed card and waited.
  3. 3Posted the entry and its 1.2 MB cover image.
3 bots on this job
Save the token in the Secret needed cardWaiting for your yes

How it works

How Secrets works.

  1. 01

    The bot asks with a card

    When a task needs a token you have not saved, a Secret needed card shows the secret's name and why the bot needs it.

  2. 02

    Check the site

    Check Sent only to. The bot suggests the site; make sure it is your real one.

  3. 03

    Save securely

    Paste the token and choose Save securely. The bot carries on, and only that bot may use it until you change that.

  4. 04

    Manage it later

    Open Settings → Secrets (under AI) to see each secret's site, allowed bots and last use, or choose Add secret.

Good to know

The details.

Three ways to send

Authorization: Bearer, a header you name such as X-API-Key, or only where the bot writes {{secret:NAME}} in the request.

File uploads too

Bots can upload files with a secret, the way a skill's curl -F command does: up to 10 MB and 50 files per request, sent only to the secret's site.

Pasted tokens are refused

If you paste a token into the chat, the bot will not use it. It tells you to rotate it and asks for the new one with the secure card.

Logged without the value

Each use is recorded with the secret's name, the site and the time, never the value.

Write-only values

A saved value is never shown again. You can replace it, change its site or bots, or delete it.

The edges, plainly

  • Secrets work in the desktop app only. They are not yet available on Brainwrite Cloud, on a server you run yourself, or from the phone apps.
  • Each secret goes to one https site. A request to any other site is refused.
  • On a Mac, uploading from folders such as Desktop or Documents needs Brainwrite allowed in System Settings → Privacy & Security → Files and Folders.
Full reference in the documentation

FAQ

Questions about Secrets

How do I give an AI agent an API key safely?

Save it as a secret instead of pasting it into chat. In Brainwrite, the bot asks with a Secret needed card; you check the site, paste the token and choose Save securely. The bot then refers to the secret by name, and Brainwrite inserts the value only when sending to that one https site.

Can the AI agent see my API key?

No. The value is kept in your computer's secure store and is never added to the chat, the bot's instructions, its shell or its logs. Brainwrite makes the request itself, never follows a redirect, and cleans the token out of the response before the bot sees it.

What happens if I paste an API key into the chat?

The bot will not use it. Because the token is now part of the conversation, the bot tells you to rotate it, then asks for the new one with the secure card. A bot should never ask you to paste a token into chat.

Do secrets work on Brainwrite Cloud?

Not yet. Secrets work in the Brainwrite desktop app, for the bots on that computer. They are not available on Brainwrite Cloud, on a server you run yourself, or from the phone apps. On another connected device, the card asks you to finish on the computer that runs your bots.

Give your first job to Brainwrite.

Download the app, connect the AI you already pay for, and tell your Chief of Staff what needs doing.

macOS today. Windows and Linux are coming soon.