Cloud

Secrets Management

AES-256-GCM authenticated encryption for secrets at rest.

2 min readDocumentationEdit this page

Overview

The secrets manager encrypts and decrypts sensitive values using AES-256-GCM, providing authenticated encryption that protects against both eavesdropping and tampering.

Usage

typescript
import { SecretsManager } from '@axiljs/cloud'
 
const secrets = new SecretsManager({
  encryptionKey: process.env.SECRETS_ENCRYPTION_KEY,
})
 
await secrets.set('DATABASE_URL', 'postgres://user:pass@host/db')
const dbUrl = await secrets.get('DATABASE_URL')
 
secrets.has('DATABASE_URL') // true
 
secrets.list()
// [{ name: 'DATABASE_URL', createdAt: '...', updatedAt: '...' }]

Key Generation

Generate a cryptographically secure 32-byte encryption key:

typescript
const key = SecretsManager.generateKey()
// 'a3f1b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1'

Store this key in your environment variables or KMS. Never commit it to source control.

Global Singleton

For convenience, a pre-configured singleton is available:

typescript
import { secrets } from '@axiljs/cloud'
 
await secrets.set('API_KEY', 'sk-...')
const key = await secrets.get('API_KEY')

Note: The singleton auto-generates a random key if none is provided. Secrets will not survive process restarts. Always provide encryptionKey in production.

Options

OptionTypeDescription
encryptionKeystring64-character hex string (32 bytes). Auto-generated if omitted.

API Reference

  • set(name, plaintext) — encrypt and store
  • get(name) — decrypt and return, or null
  • has(name) — check existence without decrypting
  • delete(name) — remove a secret
  • list() — enumerate names (values never exposed)
  • SecretsManager.generateKey() — create a new encryption key

Help improve the documentation

AxilJS is open source and documentation improvements are welcome.

AxilJS DocumentationMIT License · Built by SyntaxilitY