Skip to content
d3 Wiki
07.01

Secrets management

Secrets live in exactly one place and can be rotated in minutes.

Updated
Oct 3, 2026
On this page

Purpose

Secrets live in exactly one place and can be rotated in minutes.

The standard

  • Source of truth: [TEAM: 1Password / Bitwarden vault "Dev Secrets"]. Vercel and Supabase dashboards hold copies for runtime.

  • Never in: git, chat, docs, screenshots, AI prompts, client-side code.

  • Supabase service_role key: server-only, only in tools that need to bypass RLS (rare — justify in an ADR). anon key is public by design; RLS is the security boundary (08.03).

  • Rotation: quarterly for shared keys; immediately on suspected exposure or offboarding of anyone who had access.

  • GitHub secret scanning + push protection enabled on the org.

Procedure — rotating a key

  1. Generate the new key in the provider. 2. Update the vault entry. 3. Update Vercel/Supabase env; redeploy. 4. Verify the tool works. 5. Revoke the old key. 6. Note the rotation in the vault entry's history.

Owner: [TEAM] · Last reviewed: 2026-09