Purpose
Secrets live in exactly one place and can be rotated in minutes.
The standard
Source of truth:
[TEAM: 1Password / Bitwarden vault "Dev Secrets"]. Vercel and Supabase dashboards hold copies for runtime.Never in: git, chat, docs, screenshots, AI prompts, client-side code.
Supabase
service_rolekey: server-only, only in tools that need to bypass RLS (rare — justify in an ADR).anonkey is public by design; RLS is the security boundary (08.03).Rotation: quarterly for shared keys; immediately on suspected exposure or offboarding of anyone who had access.
GitHub secret scanning + push protection enabled on the org.
Procedure — rotating a key
Generate the new key in the provider. 2. Update the vault entry. 3. Update Vercel/Supabase env; redeploy. 4. Verify the tool works. 5. Revoke the old key. 6. Note the rotation in the vault entry's history.
Owner: [TEAM] · Last reviewed: 2026-09