Skip to main content

runtm secrets

Manage local environment secrets stored in .env.local.

Commands

How secrets work

  1. You set secrets locally with runtm secrets set
  2. Secrets are stored in .env.local (gitignored)
  3. On deploy, CLI reads and sends secrets securely
  4. Secrets are injected into Fly.io, never stored in Runtime

secrets set

Set a secret in .env.local.

Options

Examples

.env.local is automatically gitignored and cursorignored - secrets never get committed or exposed to AI assistants.

secrets get

Get a secret value from .env.local.

Examples


secrets list

List all secrets and their status.

Options

Output


secrets unset

Remove a secret from .env.local.

Declaring secrets in manifest

Define required environment variables in runtm.yaml:
See Secrets & Environment Variables for more details.