Adding Secrets to TypeScript Golem Agents
SkillAI & modelsGuides your agent through adding secret values like API keys to TypeScript Golem projects.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Adding Secrets to TypeScript Golem Agents skill
About this skill
Adding secrets to TypeScript Golem agents. Use when the user asks to add secrets, store API keys, manage sensitive config values, or use Secret<T> in TypeScript agents.
What this skill tells your AI
The instructions your AI receives, as published by golemcloud/golem in golem-skills/skills/ts/golem-add-secret-ts/SKILL.md and read by ahel’s review.
Overview
Secrets are sensitive configuration values (API keys, passwords, tokens) stored per-environment. In the TypeScript SDK a secret is just a config field marked with the s.secret(...) schema marker. The config value carries an opaque, log-safe Secret<T> handle; the plaintext is revealed only when agent code calls .get().
Declaring Secrets in the Config Record
Wrap a sensitive field's schema with s.secret(inner) in the agent's config record. Secret markers work at any depth — including a whole nested object:
import { z } from 'zod';
import { defineAgent, method, s } from '@golemcloud/golem-ts-sdk';
export const MyAgent = defineAgent({
name: 'MyAgent',
id: { name: z.string() },
config: {
// A plain local field, read fresh on each access.
greeting: z.string(),
// A top-level secret → `this.config.apiKey` is a `Secret<string>` handle.
apiKey: s.secret(z.string()),
// A nested object; its `.password` sub-field is a nested secret.
db: z.object({
host: z.string(),
port: z.number(),
password: s.secret(z.string()),
}),
},
methods: {
connect: method({ input: {}, returns: z.string() }),
},
});
this.config is statically typed from the record: greeting is a string, apiKey is a Secret<string>, and db.password is a Secret<string> (a secret wrapping a whole object would surface as Secret<{...}>).
Using Secrets in Agent Code
Call .get() on a Secret<T> field to explicitly reveal the current plaintext:
export const MyAgentImpl = MyAgent.implement({
init: () => ({}),
methods: {
connect() {
const key = this.config.apiKey.get(); // string
const pwd = this.config.db.password.get(); // string
return `Connecting to ${this.config.db.host}:${this.config.db.port}`;
},
},
});
Secret handles are log-safe: JSON.stringify / logging the whole config object throws rather than leaking the plaintext. Call .get() only where you actually need the value.
Managing Secrets via CLI
# Create secrets (--secret-type uses language-native type names)
golem secret create apiKey --secret-type string --secret-value "sk-abc123"
golem secret create db.password --secret-type string --secret-value "s3cret"
# List, update, and delete
golem secret list
golem secret update-value apiKey --secret-value "new-value"
golem secret delete apiKey
Note: For
update-valueanddelete, you can also use--id <uuid>instead of the positional path.
Secret Defaults in golem.yaml
For development environments, define secret defaults in golem.yaml. These are not used in production:
secretDefaults:
local:
apiKey: "dev-key-123"
db:
password: "dev-password"
Key Points
- Mark a config field secret with
s.secret(inner)— no separate declaration; the field becomes aSecret<T>onthis.config. Secret<T>values are not revealed eagerly — call.get()to read the current plaintext (it re-reads the live value each call).Secrethandles refuse serialization, so a stray log ofthis.configcannot leak a secret.- Secret values are stored per-environment, not per-agent-instance.
- Secrets are not stored in the
configsection ofgolem.yaml— usesecretDefaultsfor dev environments only. - Missing required secrets cause agent creation to fail.
- The
--secret-typeflag accepts TypeScript type names:string,s32,boolean,string[](JSON-encoded analysed types like'{"type":"Str"}'are also supported as a fallback). - If the agent also needs non-secret typed config guidance, use
golem-add-config-tsalongside this skill.
Signals
- GitHub stars
- 2k
- Forks
- 210
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
golem-add-secret-ts- Source
- github.com/golemcloud/golem