Sooner or later every automation needs a secret: an API key, an access token, the password for a service your team signed up for years ago. The easy thing has always been to paste it into the step that needs it. That works until you have twenty workflows, the key needs replacing, and nobody remembers every place it was pasted.
So Lodol now has a home for them. Secrets and Values, in the sidebar, keeps your workflows' credentials and everyday settings in one place, encrypted where it matters and shared by name.
Secrets: stored once, never shown again
A secret is for anything sensitive, like an API key or a token. Add it once, and it's encrypted and hidden the moment you save it. Nobody sees the value again, admins included: Lodol never displays it or returns it through its API. Any step that needs it refers to it by name, as @secrets.STRIPE_KEY, and gets the real value only at the moment the step runs.
Secret values are kept in Google Cloud's Secret Manager, not in Lodol's own database, which holds only a reference to each one. And if a step's output ever happens to contain a secret, Lodol replaces it with *** everywhere it would show up: in the run record, in step results and in error messages.
Values: the settings everyone should be able to read
Not everything a workflow needs is a secret. The spending limit above which a manager has to approve, the Slack channel alerts go to, the address the weekly report is sent to: these are settings, and the people running a workflow should be able to see them. Values are for exactly that. They stay readable, and steps use them by name too, as @values.APPROVAL_LIMIT.
Change it once, and every workflow follows
Because workflows refer to secrets and values by name, each one lives in one place. Replace an expiring key, or raise the approval limit from $500 to $1,000, in one place, and every workflow that uses it picks up the change on its next run. Pick a workflow under Used by to see every secret and value it can reach.
Who can see and change what
- Workspace-wide secrets and values are managed by owners and admins by default, and each one can be open to any workflow or limited to only the workflows you choose.
- A workflow's own secrets and values, set from the key icon in the editor, can be managed by anyone allowed to edit that workflow, and they take precedence over workspace ones with the same name.
- Workflows can never write a secret. They can change a value only if you switch on Let workflows edit this value, which is handy for something like remembering the last invoice number a workflow processed.
Secrets and Values is available on every plan.
Move your keys somewhere safe.
Open Secrets and Values from the sidebar in Lodol, add your first secret, and replace any key pasted into a step with its name. Start free if you don't have a workspace yet.
