Adding Secrets to a Scala Golem Agent
SkillAI & modelsGuides your agent through storing API keys and passwords securely in Scala Golem apps using Secret types.
Use Adding Secrets to a Scala Golem Agent in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Adding Secrets to a Scala Golem Agent and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Adding Secrets to a Scala Golem Agent skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Adding secrets to Scala Golem agents. Use when the user asks to add secret values, API keys, passwords, or sensitive configuration to a Scala Golem agent.
What this skill tells your AI
The instructions your AI receives, as published by golemcloud/golem in golem-skills/skills/scala/golem-add-secret-scala/SKILL.md and read by Ahel’s review.
Overview
Secrets are sensitive configuration values (API keys, passwords, tokens) stored per-environment and accessed via Secret[T] from golem.config. They are declared inside config case classes alongside regular config fields, but the config value carries an opaque secret handle; plaintext is revealed only when agent code calls .get.
Declaring Secrets
Wrap sensitive fields with Secret[T] in your config case class. Secret[T] has an implicit Schema derivation, so Schema.derived works automatically on parent case classes:
import golem.config.Secret
import zio.blocks.schema.Schema
final case class DbConfig(
host: String,
port: Int,
password: Secret[String],
)
object DbConfig {
implicit val schema: Schema[DbConfig] = Schema.derived
}
final case class MyAppConfig(
appName: String,
apiKey: Secret[String],
db: DbConfig,
)
object MyAppConfig {
implicit val schema: Schema[MyAppConfig] = Schema.derived
}
Reading Secrets
Secret[T] is lazy — call .get to explicitly reveal the current value:
import golem.runtime.annotations.agentImplementation
import golem.config.Config
import scala.concurrent.Future
@agentImplementation()
final class MyAgentImpl(input: String, config: Config[MyAppConfig]) extends MyAgent {
override def connect(): Future[String] = {
val cfg = config.value
val key = cfg.apiKey.get
val pwd = cfg.db.password.get
Future.successful(s"Connected to ${cfg.db.host}:${cfg.db.port}")
}
}
Managing Secrets via CLI
Secret paths use camelCase, matching Scala field names:
golem secret create apiKey --type String --value "sk-abc123"
golem secret create db.password --type String --value "s3cret"
printenv DB_PASSWORD | golem secret create db.password --type String --value-stdin
golem secret create apiKey --type String --value "sk-abc123" --update-existing
golem secret list
golem secret update apiKey --value "new-value"
golem secret update apiKey --unset
golem secret delete apiKey
Note: Without a value option,
createandupdateprompt for the value (hidden input).--update-existingupdates the value of an existing secret instead of failing.deleteasks for confirmation (--yesskips it). Forupdateanddelete, you can also use--id <uuid>instead of the positional path.
Secret Defaults in golem.yaml
Use secretDefaults for local development only — manage production secrets via CLI:
secretDefaults:
local:
apiKey: "dev-key-123"
db:
password: "dev-password"
Key Constraints
Secret[T]is lazy — call.getto reveal the actual value- Each reveal pins the resolved secret revision for deterministic retries and replay; fresh
.getcalls can observe runtime updates - Secret values are stored per-environment, not per-agent-instance
- The
Secret[T]companion provides an implicitSchemasoSchema.derivedworks on parent case classes - Missing required secrets cause agent creation to fail
- Secret paths use camelCase (matching Scala field names)
- The
--typeargument accepts Scala type names:String,Int,Boolean,List[String],Option[Int](if parsing as Scala fails, the other supported languages' type syntax is tried) - Use
secretDefaultsingolem.yamlonly for development; manage production secrets via CLI - If the agent also needs non-secret typed config guidance, use
golem-add-config-scalaalongside this skill
Signals
- GitHub stars
- 2k
- Forks
- 210
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
golem-add-secret-scala- Source
- github.com/golemcloud/golem
More in AI & models
Skill · anthropics
More in AI & modelstriage
Skill · mattpocock
More in AI & modelswayfinder
Skill · mattpocock
More in AI & modelsalgorithmic-art
Skill · anthropics
More in AI & modelscode-review-and-quality
Skill · addyosmani
More in AI & modelsmarketing-psychology
Skill · coreyhaines31
More in AI & models