Environment Variables
Install Environment Variables, configure its capabilities and verify a bounded operation.
The internal builtin:env-secrets provider resolves env://NAME from the execution process environment. It is an operator-configured capability, not a way for workspace users to upload arbitrary environment variables.
Install
You need a Semogram account with workspace access. Ask the deployment operator to confirm that the environment provider is enabled for the relevant runtime and the requested variable is explicitly allowed.
- Identify the credential needed by a connector.
- Have the operator configure that credential in the execution environment.
- Have the operator enable the provider and restrict allowed variable names.
- Inspect the Environment Variables capability in Plugins if it is exposed by your deployment. A catalog entry alone does not register a provider in every runtime.
Make your first read
Use a reference in a protected installation field supported by the execution path:
In the connector installation form, enter env://OPERATIONS_DB_PASSWORD into its protected Password field. The deployment operator must first enable the provider and allow this variable; the UI does not create the environment secret.
The object below represents the target/settings in this example. It is not a complete API or MCP request. Use it in the matching configuration/target field of that operation, with the real resource IDs required by its schema.
{ "password": "env://OPERATIONS_DB_PASSWORD" }Run the connector’s bounded check or read. Verify successful authentication without printing the resolved secret. Resolution fails if the variable is absent or disallowed.
Manage the connection
Rotate the environment value through the deployment operator, then rerun the connector check. The provider supports an explicit name list or regular-expression allowlist in the runtime; tenant input must not receive unrestricted access to the host’s environment.
The registry contains a secret_resolution contract with an optional prefix. That declaration is not proof that prefix isolation is automatically enforced: inspect the deployed provider configuration and allowed names.
FAQ
Can I add a secret by putting it in my local shell?
Only if that is the actual process running the operation. A variable on your laptop is not automatically present in a hosted worker or sandbox.
Does a secret field guarantee all exports are redacted?
No. Keep credentials out of prompts, package files and evidence. Verify the relevant export and logging paths instead of assuming a schema hint covers every surface.
Is this provider always available?
No. It is never registered implicitly by the core provider. Deployment configuration must opt in. See configuration and troubleshooting.