Read secrets from an SDK
Read the values your application needs at runtime with the SDKs or Refine. Create and manage secrets through TaruviBase Console.
This page covers JavaScript SDK 1.5.4 and Python SDK 0.2.3.
Prerequisites#
- Create the type and value through TaruviBase Console.
- Configure a JavaScript
secretsclient or Pythonclientfor the intended site and app. See JavaScript or Python. - Use the exact existing key. The API schema caps keys at 255 characters.
Read one secret#
- JavaScript SDK
- Python SDK
- Refine
import type {SecretResponse} from '@taruvi/sdk';
await secrets
.get('app_config', {app: 'APP_SLUG'})
.execute<SecretResponse>();
client.secrets.get("app_config", app="APP_SLUG")
Configure the named app provider using Refine setup.
Refine runs in the browser. Use it for configuration intended for that user; read server credentials on the server. Put the hook inside your React component.
import {useOne} from '@refinedev/core';
useOne({
dataProviderName: 'app',
resource: 'secrets',
id: 'app_config',
meta: {app: 'APP_SLUG'},
});
The hook’s result contains the secret object after query.isSuccess. Do not
log its value.
JavaScript execute() returns the standard response wrapper, so read the
secret from its data field. Python get() returns the extracted secret object.
A Python client substitutes its configured app_slug when app is omitted;
pass the app explicitly when scope must be obvious in code. The JavaScript
Secrets helper uses its explicit app option. All three examples above
request APP_SLUG.
Retrieve several secrets#
Fetch up to 100 keys in one call. Missing or sensitivity-denied keys are omitted rather than returned with empty values.
- JavaScript SDK
- Python SDK
- Refine
await secrets.list(['app_config', 'feature_flags'], {
app: 'APP_SLUG',
includeMetadata: true,
});
client.secrets.list(
keys=["app_config", "feature_flags"],
app="APP_SLUG",
include_metadata=True,
)
Configure the named app provider using Refine setup.
Refine runs in the browser. Use it for configuration intended for that user; read server credentials on the server. Put the hook inside your React component.
import {useList} from '@refinedev/core';
useList({
dataProviderName: 'app',
resource: 'secrets',
meta: {
keys: ['app_config', 'feature_flags'],
app: 'APP_SLUG',
includeMetadata: true,
},
});
The hook’s result.data contains key/value entries. With
includeMetadata: true, each value contains the value and its metadata.
Missing or denied keys stay absent. Check the hook’s query.isSuccess before
consuming them.
Both SDK list() methods return the response wrapper; the requested map is in
data. Values can be strings or JSON objects; check the value's shape before
using it.
Verify without exposing values#
Check that the expected keys are present and that the value has the expected type. Do not print, snapshot, or attach the value to logs, traces, tickets, or test output. If a key is missing, confirm site/app scope and sensitivity before retrying.