Adding Secrets to TypeScript Golem Agents
SkillAI & modelsShows your agent how to safely store and use API keys and other secrets in TypeScript Golem agents.
Use Adding Secrets to TypeScript Golem Agents in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Adding Secrets to TypeScript Golem Agents and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Adding Secrets to TypeScript Golem Agents skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Adding secrets to TypeScript Golem agents. Use when the user asks to add secrets, store API keys, manage sensitive config values, or use Secret<T> in TypeScript agents.
What this skill tells your AI
The instructions your AI receives, as published by golemcloud/golem in golem-skills/skills/ts/golem-add-secret-ts/SKILL.md and read by Ahel’s review.
Overview
Secrets are sensitive configuration values (API keys, passwords, tokens) stored per-environment. In the TypeScript SDK a secret is just a config field marked with the s.secret(...) schema marker. The config value carries an opaque, log-safe Secret<T> handle; the plaintext is revealed only when agent code calls .get().
Declaring Secrets in the Config Record
Wrap a sensitive field's schema with s.secret(inner) in the agent's config record. Secret markers work at any depth — including a whole nested object:
import { z } from 'zod';
import { defineAgent, method, s } from '@golemcloud/golem-ts-sdk';
export const MyAgent = defineAgent({
name: 'MyAgent',
id: { name: z.string() },
config: {
// A plain local field, read fresh on each access.
greeting: z.string(),
// A top-level secret → `this.config.apiKey` is a `Secret<string>` handle.
apiKey: s.secret(z.string()),
// A nested object; its `.password` sub-field is a nested secret.
db: z.object({
host: z.string(),
port: z.number(),
password: s.secret(z.string()),
}),
},
methods: {
connect: method({ input: {}, returns: z.string() }),
},
});
this.config is statically typed from the record: greeting is a string, apiKey is a Secret<string>, and db.password is a Secret<string> (a secret wrapping a whole object would surface as Secret<{...}>).
Using Secrets in Agent Code
Call .get() on a Secret<T> field to explicitly reveal the current plaintext:
export const MyAgentImpl = MyAgent.implement({
init: () => ({}),
methods: {
connect() {
const key = this.config.apiKey.get(); // string
const pwd = this.config.db.password.get(); // string
return `Connecting to ${this.config.db.host}:${this.config.db.port}`;
},
},
});
Secret handles are log-safe: JSON.stringify / logging the whole config object throws rather than leaking the plaintext. Call .get() only where you actually need the value.
Managing Secrets via CLI
# Create secrets (--type uses language-native type names)
golem secret create apiKey --type string --value "sk-abc123"
golem secret create db.password --type string --value "s3cret"
# Without a value option the value is prompted for (hidden input); or pipe it in
printenv DB_PASSWORD | golem secret create db.password --type string --value-stdin
# Create, or update the value if the secret already exists
golem secret create apiKey --type string --value "sk-abc123" --update-existing
# List, update, clear, and delete (delete asks for confirmation; --yes skips it)
golem secret list
golem secret update apiKey --value "new-value"
golem secret update apiKey --unset
golem secret delete apiKey
Note: For
updateanddelete, you can also use--id <uuid>instead of the positional path.
Secret Defaults in golem.yaml
For development environments, define secret defaults in golem.yaml. These are not used in production:
secretDefaults:
local:
apiKey: "dev-key-123"
db:
password: "dev-password"
Key Points
- Mark a config field secret with
s.secret(inner)— no separate declaration; the field becomes aSecret<T>onthis.config. Secret<T>values are not revealed eagerly — call.get()to read the current plaintext (it re-reads the live value each call).Secrethandles refuse serialization, so a stray log ofthis.configcannot leak a secret.- Secret values are stored per-environment, not per-agent-instance.
- Secrets are not stored in the
configsection ofgolem.yaml— usesecretDefaultsfor dev environments only. - Missing required secrets cause agent creation to fail.
- The
--typeflag accepts TypeScript type names:string,s32,boolean,string[](if parsing as TypeScript fails, the other supported languages' type syntax is tried). - If the agent also needs non-secret typed config guidance, use
golem-add-config-tsalongside this skill.
Signals
- GitHub stars
- 2k
- Forks
- 210
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
golem-add-secret-ts- Source
- github.com/golemcloud/golem
Related picks
Skill · mattpocock
The pick for TypeScripttypescript-pro
Skill · jeffallan
The pick for TypeScriptskill-creator
Skill · anthropics
More in AI & modelstriage
Skill · mattpocock
More in AI & modelsalgorithmic-art
Skill · anthropics
More in AI & modelscode-review-and-quality
Skill · addyosmani
More in AI & models