- Only W&B Admins can create, edit, or delete a secret.
- Secrets are included as a core part of W&B, including in W&B Server deployments that you host in Azure, GCP, or AWS. Connect with your W&B account team to discuss how you can use secrets in W&B if you use a different deployment type.
-
In W&B Server, you are responsible for configuring security measures that satisfy your security needs.
- W&B strongly recommends that you store secrets in a W&B instance of a cloud provider’s secrets manager provided by AWS, GCP, or Azure, which are configured with advanced security capabilities.
- W&B recommends against using a Kubernetes cluster as the backend of your secrets store unless you are unable to use a W&B instance of a cloud secrets manager (AWS, GCP, or Azure), and you understand how to prevent security vulnerabilities that can occur if you use a cluster.
Add a secret
To add a secret:- If the receiving service requires it to authenticate incoming webhooks, generate the required token or API key. If necessary, save the sensitive string securely, such as in a password manager.
- Log in to W&B and go to the team’s Settings page.
- In the Team Secrets section, click New secret.
- Using letters, numbers, and underscores (
_
), provide a name for the secret. - Paste the sensitive string into the Secret field.
- Click Add secret.
Once you create a secret, you can access that secret in a webhook automation’s payload using the format
${SECRET_NAME}
.Rotate a secret
To rotate a secret and update its value:- Click the pencil icon in the secret’s row to open the secret’s details.
- Set Secret to the new value. Optionally click Reveal secret to verify the new value.
- Click Add secret. The secret’s value updates and no longer resolves to the previous value.
After a secret is created or updated, you can no longer reveal its current value. Instead, rotate the secret to a new value.
Delete a secret
To delete a secret:- Click the trash icon in the secret’s row.
- Read the confirmation dialog, then click Delete. The secret is deleted immediately and permanently.