For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
Docs Menu

agentengine secret set

Set or update a secret.

Set or update a secret in the project or workspace secret store.

The platform requires MONGODB_URI, plus VOYAGE_API_KEY when features.memory is true. Provider keys such as ANTHROPIC_API_KEY and OPENAI_API_KEY are agent-specific; set the ones your agent uses.

Names match ^[A-Z][A-Z0-9_]{0,127}$, may not be reserved platform names, and cannot start with AGENTIC_PLATFORM_. This sets project-scoped secrets by default; --workspace-scope or --workspace-id targets a workspace. --context names the organization and project only, so combine it with --project-scope.

Omit the value for a hidden prompt, or pipe it with --stdin. Positional VALUE and --value are deprecated. Bulk dotenv import uses --from-file (- for stdin). --from-file reads plaintext secrets. Prefer a masked prompt or stdin from a secret manager. If you use a file, make it owner-only, import it once, then delete it and remove copies from history, backups, and version control, and rotate every imported secret if it may have been committed or exposed. Do not commit or sync the file. File paths work on Linux only, so use --from-file - on macOS and Windows.

--on-empty controls empty values in an import: skip, warn, or error. The default is to prompt on an interactive terminal and to error otherwise.

--sync waits until the next message can use the new values. The current turn keeps the old ones.

Examples:

agentengine secret set MONGODB_URI secret-manager
export-dotenv \| agentengine secret set --from-file - agentengine secret
set API_KEY --workspace-scope
agentengine secret set [NAME] [flags]
--base-url string Platform base URL
--context string Named context to target (see 'agentengine context list')
--description string Human-readable description of the secret
--from-file string Security warning: import plaintext dotenv secrets from a private temporary Linux file, or - for stdin on any OS
-h, --help help for set
--on-empty string Action for empty values when using --from-file: skip, warn, or error
--org-id string Organization ID
--project-id string Project ID
--project-scope Target project-scoped secrets (the default; explicit alternative to --workspace-scope)
--stdin Read the entire stdin stream as one secret; use --from-file - for dotenv
--sync After setting, wait until the next message can use the new secret values
--workspace string Monorepo: target a specific workspace by name (from root agent.yaml)
--workspace-id string Workspace ID
--workspace-scope Target workspace-scoped secrets instead of project-scoped secrets (the default)
--log-file string override log file path
--log-level string file log verbosity (error|warn|info|debug) (default "info")
--no-log disable file logging
-q, --quiet silence stderr below error
-v, --verbose count raise stderr verbosity (-v info, -vv debug)
Rate this page