Secrets keep credentials on the host while giving sandboxed code a placeholder to use.When you bind a secret to an environment variable, microsandbox puts a placeholder in the guest instead of the real value. By default that placeholder is $MSB_<env_var>, using the environment variable name exactly as provided, and you can provide a custom placeholder when needed. If the sandbox sends the placeholder to an allowed host, microsandbox swaps it for the real credential at the network boundary. Anywhere else, the placeholder remains meaningless.That means the guest can call APIs without ever holding the credential itself.microsandbox checks allowed hosts against the sandbox’s observed DNS and TLS identity. Keep allow lists narrow so placeholders can only turn into credentials at the destinations that actually need them.
In the CLI form, ENV@HOST[,HOST...] records a host-side source reference: the real value is read from the same-named host environment variable when the sandbox starts, and never lands in the durable config. The inline ENV=VALUE@HOST form is rejected on both msb create and msb modify (shell history and process listings would leak the value regardless), so providing a raw value is SDK-only.
Raw values are saved to disk. When you pass a raw value through an SDK (.value(..), secret_env(), or a value-based rotate), it is stored as-is in the sandbox config file and stays there until you rotate the secret to a reference. The sandbox behaves the same either way; the only difference is what ends up on disk. Prefer references whenever the value is available in a host environment variable.
Rotate or remove existing secrets without a restart. Adding a secret or changing its guest-visible placeholder requires a restart so the new environment reaches the guest. Later rotations keep that placeholder stable and only change the value injected at the network boundary.
Secret modification is available through every SDK and the CLI. See Live Modify for how changes are planned and applied.For API details, see the SDK references: TypeScript | Rust | Python | Go.
Was this page helpful?
⌘I
Assistant
Responses are generated using AI and may contain mistakes.