Docs
Reference

CircleCI context

Export secrets into a CircleCI context.

Export secrets into a CircleCI context.

The connection

WhatThis provider
VendorCircleCI
Keycircleci-context
Availabilityavailable. You can connect it today.
Credential penv holdscircleci-token
Values read backno
Activationimmediate

What it moves

DirectionWhat it does
exportWrites names and values from penv into the store.

CircleCI returns no value once it holds one, so penv can write here and cannot read back.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenPersonal API tokensecret, masked here and sealedyesUse a personal token. Project tokens do not work on CircleCI's v2 API, and one minted before June 2023 is refused by context endpoints.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
contextIdContext IDtextyesnoThe last part of the context's URL in CircleCI's organization settings.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
me:readevery directionyesWe cannot confirm which CircleCI account this token belongs to.
context:writeexportyesExport cannot write anything.